Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Certighost Flaw in AD CS Allows Domain Compromise

Certighost Flaw in AD CS Allows Domain Compromise

Posted on July 24, 2026 By CWS

An Active Directory Certificate Services (AD CS) vulnerability known as Certighost, identified as CVE-2026-54121, was recently revealed. This flaw allows low-privilege users to impersonate a Domain Controller, potentially leading to complete control over an Active Directory domain.

Understanding Certighost and Its Impact

The Certighost vulnerability was addressed in Microsoft’s July 2026 security updates. This flaw affects Microsoft’s public key infrastructure (PKI), which issues X.509 certificates for encryption, signing, and authentication within domains. These certificates function similarly to digital IDs, with a Certification Authority (CA) authorizing them by linking a public key to a particular identity.

The vulnerability is particularly critical in scenarios involving certificate-based Kerberos authentication (PKINIT). Here, the flaw disrupts the correlation between a certificate and its associated AD account, due to issues in the mapping process performed by the Key Distribution Center (KDC).

Technical Details of the Vulnerability

Certighost exploits a specific aspect of the CA’s operations: a secondary directory inquiry known as a chase. This process is influenced by two attributes: cdc (Client DC) and rmd (Remote Domain). The vulnerability arises because the CA does not verify whether the host specified in the cdc attribute is a legitimate Domain Controller.

By setting up malicious SMB, LDAP, and LSA services, attackers can manipulate the CA into accepting false identity data. This includes supplying a real Domain Controller’s Security Identifier (SID) and DNS hostname for the rmd target, thus bypassing normal authentication checks.

Mitigation and Future Outlook

To mitigate the risk, Microsoft introduced a validation function, _ValidateChaseTargetIsDC, in its July patch. This function performs several checks, such as rejecting invalid hostnames and confirming the target’s authenticity as a computer object. Only if these criteria are met does the CA proceed with the chase and issue the certificate.

For organizations unable to immediately apply the July patch, a temporary workaround involves disabling the vulnerable chase feature through a specific command. However, this is not a permanent solution, and organizations are urged to prioritize patching.

A proof-of-concept has been published on GitHub, emphasizing the urgency for enterprises utilizing AD CS to update their systems and audit relevant settings to prevent exploitation.

Strengthening security operations by integrating advanced threat detection tools can further safeguard against such vulnerabilities.

Cyber Security News Tags:Active Directory, AD CS, Certificate Services, Certighost, CVE-2026-54121, cyber attack prevention, Cybersecurity, digital certificates, domain controller, domain security, IT security, Kerberos authentication, Microsoft patch, security update, vulnerability patch

Post navigation

Previous Post: Tego AI Reveals Second Security Issue in Claude Software
Next Post: Critical Bing Images Flaws Patched Amid Security Concerns

Related Posts

Cisco Identity Services Engine Vulnerability Allows Attackers to Restart ISE unexpectedly Cisco Identity Services Engine Vulnerability Allows Attackers to Restart ISE unexpectedly Cyber Security News
Threat Actors Leverage Real Enterprise Email Threads to Deliver Phishing Links Threat Actors Leverage Real Enterprise Email Threads to Deliver Phishing Links Cyber Security News
Chrome Security Update Patches Critical Remote Code Execution Vulnerability Chrome Security Update Patches Critical Remote Code Execution Vulnerability Cyber Security News
Critical SAP S/4HANA Vulnerability Actively Exploited to Fully Compromise Your SAP System Critical SAP S/4HANA Vulnerability Actively Exploited to Fully Compromise Your SAP System Cyber Security News
Malicious Document Reader App in Google Play With 50K Downloads Installs Anatsa Malware Malicious Document Reader App in Google Play With 50K Downloads Installs Anatsa Malware Cyber Security News
Developers Warned of OpenVSX Aqua Trivy Exploit Developers Warned of OpenVSX Aqua Trivy Exploit Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Critical Bing Images Flaws Patched Amid Security Concerns
  • Certighost Flaw in AD CS Allows Domain Compromise
  • Tego AI Reveals Second Security Issue in Claude Software
  • SourTrade Malvertising Evades Detection with Unique Malware
  • Microsoft Ends Unwanted Ads in Windows 11

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Critical Bing Images Flaws Patched Amid Security Concerns
  • Certighost Flaw in AD CS Allows Domain Compromise
  • Tego AI Reveals Second Security Issue in Claude Software
  • SourTrade Malvertising Evades Detection with Unique Malware
  • Microsoft Ends Unwanted Ads in Windows 11

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark