Certighost Exploit Allows Low-Privileged AD Users to Impersonate Domain Controllers

The Certighost exploit enables low-privileged Active Directory users to obtain Domain Controller certificates and authenticate as domain controllers, risking critical Kerberos credential compromise.

Why it matters

This vulnerability allows attackers to impersonate domain controllers, increasing the risk of unauthorized access to sensitive Kerberos credentials and potential domain compromise.

SOC impact

Analyze authentication logs for unusual domain controller certificate enrollments and anomalous Kerberos activity. Investigate any unexpected issuance of domain controller certificates by low-privileged accounts and monitor for indicators of DCSync-like behaviors.

Recommended actions

  1. Identify assets with domain controller certificate enrollment capabilities
  2. Review certificate issuance logs for suspicious activity
  3. Monitor Kerberos ticket requests for irregular patterns
  4. Investigate low-privileged accounts requesting privileged certificates
  5. Assess potential exposure to DCSync attack techniques

Executive Summary

Researchers have identified the Certighost exploit, which enables low-privileged Active Directory users to acquire domain controller certificates and authenticate as domain controllers. This access to critical Kerberos credentials significantly increases the risk of domain compromise via DCSync attacks. Operationally, this exploit challenges traditional trust boundaries in AD environments and calls for focused monitoring of certificate issuance and Kerberos authentication processes to detect potential misuse.

SOC Impact

Analyze authentication logs for unusual domain controller certificate enrollments and anomalous Kerberos activity. Investigate any unexpected issuance of domain controller certificates by low-privileged accounts and monitor for indicators of DCSync-like behaviors.

Authentication and Access Validation

  • Identify assets with domain controller certificate enrollment capabilities
  • Review certificate issuance logs for suspicious activity
  • Monitor Kerberos ticket requests for irregular patterns
  • Investigate low-privileged accounts requesting privileged certificates
  • Assess potential exposure to DCSync attack techniques

Why It Matters

This vulnerability allows attackers to impersonate domain controllers, increasing the risk of unauthorized access to sensitive Kerberos credentials and potential domain compromise.

Source