Certighost enables low-privileged AD users to impersonate a Domain Controller
Source headline: Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller
Intelligence Summary
Researchers disclosed the Certighost exploit, which allows low-privileged Active Directory users to obtain a certificate for a Domain Controller. Using that certificate, an attacker can authenticate as the domain controller machine identity. Because domain controller accounts have directory replication rights, the resulting Kerberos credential can be used to reach the krbtgt secret via DCSync. Compromising krbtgt can enable broader persistence and domain compromise. Organizations using Active Directory should review exposure and harden certificate and replication-related controls, and monitor for related authentication and replication anomalies.
Recommended Action
Prioritize immediate review, validate exposure, and patch or mitigate affected systems.