hacker-news · Crawled Jul 24, 2026

Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller

2 IoCs
Read original article ↗

AI Summary

Researchers H0j3n and Aniq Fakhrul disclosed a working exploit named Certighost that enables low-privileged Active Directory users to impersonate a Domain Controller by obtaining a certificate via a vulnerable AD CS enrollment fallback mechanism. The exploit abuses improper validation of the chase target during certificate enrollment, allowing attackers to relay authentication and obtain a certificate for a Domain Controller. This can lead to privilege escalation via DCSync to extract sensitive account secrets such as krbtgt, even without administrator rights.

AI-extracted · verify before operational use

Indicators of Compromise 2 extracted

Type Value Detail
GitHub User H0j3n Details →
GitHub User AniqFakhrul Details →