Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Firefighters hasten efforts to contain massive wildfires in France and Spain ahead of heatwave – Europe live | France

    July 28, 2026

    Europe’s AI safety rules take on US rogue agents and Chinese ambitions – POLITICO

    July 28, 2026

    Burnham’s education plan directly contradicts Labour’s Schools Act, Tories claim – UK politics live | Politics

    July 28, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Firefighters hasten efforts to contain massive wildfires in France and Spain ahead of heatwave – Europe live | France
    • Europe’s AI safety rules take on US rogue agents and Chinese ambitions – POLITICO
    • Burnham’s education plan directly contradicts Labour’s Schools Act, Tories claim – UK politics live | Politics
    • Amazon’s trying to launch a global satellite cellphone network in 2028
    • Microsoft AI Releases MAI-Cyber-1-Flash: A 5B-Active-Parameter Cyber Model That Pushes MDASH to 95.95% on CyberGym
    • Coca-Cola confirms data theft in Fairlife ransomware attack
    • Russia’s Sberbank Sets December Deadline For Crypto Buildout
    • Why losing the wrong fat can trigger diabetes
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Tuesday, July 28
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    New Certighost PoC exploit lets attackers hijack Windows domains

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKJuly 28, 2026 Cybersecurity No Comments4 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    A proof-of-concept exploit for “Certighost,” a Windows Active Directory Certificate Services vulnerability, has been released that can allow authenticated attackers to potentially compromise a Windows domain.

    Tracked as CVE-2026-54121, the vulnerability was fixed by Microsoft as part of the July 2026 Patch Tuesday security updates.

    “An authenticated attacker could manipulate attributes associated with a machine account and obtain a certificate from Active Directory Certificate Services that allows authentication as that machine via PKINIT,” Microsoft explained.

    image

    If the attacker can target a domain controller account, Microsoft says they could authenticate as the domain controller and perform privileged Active Directory operations.

    Security researchers H0j3n and Aniq Fakhrul reported the vulnerability to Microsoft on May 14, 2026, with Microsoft fixing the flaw in the July security updates.

    Last week, the researchers publicly disclosed the technical details regarding the vulnerability, including the release of an exploit that can be used to gain domain-level administrative capabilities.

    “Certighost is an Active Directory Certificate Services (AD CS) vulnerability that allowed a low-privileged domain user to impersonate a Domain Controller and achieve domain compromise in the tested AD CS configuration,” reads the researchers’ technical writeup.

    Abusing the AD CS chase mechanism

    Active Directory Certificate Services (AD CS) is Microsoft’s public key infrastructure for Windows domains and is used to issue certificates for authentication and secure communications.

    During certificate-based authentication, the domain controller verifies which Active Directory account the certificate belongs to and then issues Kerberos credentials.

    Certighost affects a fallback mechanism used by AD CS during certificate enrollment requests, which the researchers refer to as a “chase,” that uses two certificate request values:

    • cdc, or Client DC, identifies the server the Certification Authority should contact.

    • rmd, or Remote Domain, identifies the account the CA should search for.

    When both attributes are supplied, the CA connects to the server specified in the cdc value and searches for the specified rmd.

    However, systems previously did not verify that the server supplied through the attacker-controlled cdc value was a legitimate domain controller.

    This allowed an attacker to run rogue SMB, LSA, and LDAP services, direct the CA to the attacker-controlled system, and return false directory information for a targeted machine account.

    Certighost attack flow
    Certighost attack flow
    Source: H0j3n and Aniq Fakhrul

    In the attack demonstrated by the researchers, a low-privileged user first creates a machine account, which is permitted under the default ms-DS-MachineAccountQuota configuration.

    “A machine account created through the default ms-DS-MachineAccountQuota setting is a valid domain principal,” reads the report.

    “This allowed the attacker-controlled chase endpoint to satisfy the authentication checks needed for the CA to continue, even though it was not the Domain Controller being impersonated.”

    The attacker then submits a certificate request that directs the CA to the rogue services and targets a domain controller account. Because the CA trusts the identity information returned by the attacker-controlled services, it issues a certificate that can be used to authenticate as that domain controller and perform Active Directory operations.

    The released certighost.py proof-of-concept automates this process by using the certificate to authenticate through PKINIT as the targeted domain controller, saving the resulting Kerberos credentials to a .ccache file and extracting the account’s NT hash.

    The researchers then demonstrated using the saved Kerberos credentials with Impacket’s secretsdump tool to perform a DCSync attack and retrieve the krbtgt account’s credentials.

    “A Domain Controller account has directory replication rights. With the resulting Kerberos credential, the attacker can request account secrets, including the krbtgt secret,” explained the researchers.

    Using the DC's Kerberos credentials to perform a DCSync attack
    Using the DC’s Kerberos credentials to perform a DCSync attack
    Source: H0j3n and Aniq Fakhrul

    Microsoft fixed the vulnerability as part of the July Patch Tuesday updates by adding validation to this chase process.

    The CA now verifies that the server specified in the cdc attribute maps to a legitimate domain controller in Active Directory and confirms that the returned identity matches the expected account. 

    For admins who cannot install the July security updates, the researchers say that you can disable the optional chase fallback using the following commands:

    
    certutil -setreg policyEditFlags -EDITF_ENABLECHASECLIENTDC
    Restart-Service CertSvc -Force

    However, the researchers stress that this workaround is only a temporary mitigation and has not been fully tested in production environments. Therefore, admins should prioritize installing the latest security updates as soon as possible.


    article image

    Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.

    The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.

    Get the whitepaper

    Attackers Certighost Domains exploit hijack lets PoC Windows
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Coca-Cola confirms data theft in Fairlife ransomware attack

    Microsoft Says New Cybersecurity AI Model Helps MDASH Hit 95.95% at Half the Cost

    NVIDIA Forms 37-Member Open Secure AI Alliance and Open-Sources NOOA Framework

    New Dysphoria DDoS botnet spreads to 200k devices worldwide

    Arista patches VeloCloud Orchestrator zero-day exploited in attacks

    Hacked Public Wi-Fi Gateways Used to Harvest Corporate Credentials

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Firefighters hasten efforts to contain massive wildfires in France and Spain ahead of heatwave – Europe live | France

    July 28, 2026

    Europe’s AI safety rules take on US rogue agents and Chinese ambitions – POLITICO

    July 28, 2026

    Burnham’s education plan directly contradicts Labour’s Schools Act, Tories claim – UK politics live | Politics

    July 28, 2026

    Amazon’s trying to launch a global satellite cellphone network in 2028

    July 28, 2026
    Latest Posts

    The Western Myth of Russian Greatness – Foreign Policy

    July 21, 2026

    Defence stocks rally as John Healey appointed chancellor; UK borrows less than expected in June – business live | Business

    July 21, 2026

    You Pay for Internet Service in Empty Buildings on Alaska’s Adak Island — ProPublica

    July 21, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Firefighters hasten efforts to contain massive wildfires in France and Spain ahead of heatwave – Europe live | France

    July 28, 2026

    Europe’s AI safety rules take on US rogue agents and Chinese ambitions – POLITICO

    July 28, 2026

    Burnham’s education plan directly contradicts Labour’s Schools Act, Tories claim – UK politics live | Politics

    July 28, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.