Certighost haunts Microsoft Active Directory Certificate Services

Summary

A vulnerability dubbed Certighost in Microsoft's Active Directory Certificate Services (AD CS) could allow a low-privilege user to impersonate a Domain Controller. Attackers can exploit a certificate issuance fallback mechanism to trick the CA into accepting an attacker-controlled identity. Microsoft has patched this vulnerability.

IFF Assessment

FOE

This vulnerability allows attackers to impersonate Domain Controllers, which is a critical threat to network security and trust.

Severity

8.8 High (AI Estimated)

The vulnerability allows a low-privilege attacker to impersonate a Domain Controller by manipulating the certificate issuance process, leading to significant impact on confidentiality, integrity, and availability. The attack requires network access and attacker-controlled infrastructure, but the exploitability is high due to the trust relationship within AD CS.

Defender Context

This Certighost vulnerability in AD CS highlights the importance of securing certificate services, as misconfigurations or inherent flaws can lead to severe compromise. Defenders should ensure AD CS is properly configured, monitor for unusual certificate enrollment requests, and promptly apply security patches to prevent such impersonation attacks.

Read Full Story →