New Certighost PoC exploit lets attackers hijack Windows domains

Summary

A proof-of-concept exploit for a vulnerability named "Certighost" in Windows Active Directory Certificate Services has been released. This exploit enables authenticated attackers to potentially gain control of an entire Windows domain.

IFF Assessment

FOE

The release of a proof-of-concept exploit for a critical Active Directory vulnerability poses a significant risk to organizations, as it lowers the barrier for attackers to compromise entire Windows domains.

Severity

9.1 Critical (AI Estimated)

This vulnerability, when exploited via Certighost, allows for a critical impact on confidentiality, integrity, and availability within an Active Directory domain, and can be exploited with relative ease by authenticated users.

Defender Context

Defenders should prioritize patching or mitigating vulnerabilities related to Active Directory Certificate Services immediately. The availability of a PoC means attackers can more easily weaponize this flaw, increasing the urgency for organizations to secure their domain controllers.

Read Full Story →