CertiGHOST PoC shows how AD CS abuse could hijack Windows certificate trust
Source headline: New Certighost PoC exploit lets attackers hijack Windows domains
Intelligence Summary
A proof-of-concept exploit has been published for CertiGHOST, a vulnerability in Windows Active Directory Certificate Services. The PoC targets environments where attackers can authenticate before triggering the flaw. Successful exploitation may enable compromise of Windows Active Directory domains by abusing certificate-related trust mechanisms. This increases the risk of impersonation, privilege escalation, and broader domain control. Organizations using AD CS should review exposure, apply available mitigations or patches, and monitor for suspicious certificate-service activity.
Recommended Action
Review affected assets, schedule urgent remediation, and monitor related indicators.