Digest
CRITICAL

Certighost Exploit Allows Low-Privileged AD Users to Impersonate Domain Controllers

Researchers have published a working exploit, codenamed ‘Certighost,’ that allows a low-privileged Active Directory user to obtain a certificate for a Domain Controller and authenticate as that machine. This critical flaw grants directory replication rights, enabling the attacker to retrieve the ‘krbtgt’ secret via DCSync. The ability to impersonate a Domain Controller provides full control over the Active Directory environment, posing a severe risk.

← Back to the feed

Trending Tags