TGViewer
Ralf Hacker Channel Ralf Hacker Channel @ralfhackerchannel · 28.3K subscribers
Post #1682 12.1K

Forwarded from APT

🔒 Certighost (CVE-2026-54121) — AD CS Domain Controller Impersonation

Low-privileged domain user can impersonate a Domain Controller via an AD CS enrollment chase fallback. By supplying cdc (Client DC) and rmd (Remote Domain) request attributes, an attacker forces the Enterprise CA to query an attacker-controlled host over SMB and LDAP.

The CA then blindly trusts the returned directory objects (objectSid + dNSHostName of a real DC) and issues a certificate containing strong identity mapping for the Domain Controller. This allows successful PKINIT authentication as the DC.

🔗 Research:
https://gist.github.com/H0j3n/a5ef2609b5f2944ac2390a191a534c26

🔗 Source:
https://github.com/aniqfakhrul/CVE-2026-54121

#ad #adcs #pkinit #machineaccountquota
  • 🔥 30
  • 👍 8
More from @ralfhackerchannel
  1. Sep 18, 2026cups2root Linux LPE Interactive root shell from a local account in the lpadmin group.
  2. Sep 8, 2026Продолжается https://github.com/MSNightmare/ShieldCrash Windows Defender 0day Vulnerabilit…
  3. Sep 3, 2026Идем дальше https://github.com/MSNightmare/FalconFlank Crowdstrike Falcon 0day LPE #lpe #a…
  4. Aug 13, 2026VHDVomit A tool to search SMB shares for VHD/VMDK/VHDX backup files, mount them and dump s…
  5. Aug 11, 2026Он опять это сделал) https://github.com/MSNightmare/ShieldBreak Windows Defender LPE 0day…
  6. Jun 26, 2026DirtyClone — CVE-2026-43503 A Linux kernel local privilege escalation and page-cache write…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →