Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Certighost Flaw in AD CS Allows Domain Compromise

Certighost Flaw in AD CS Allows Domain Compromise

Posted on July 24, 2026 By CWS

An Active Directory Certificate Services (AD CS) vulnerability known as Certighost, identified as CVE-2026-54121, was recently revealed. This flaw allows low-privilege users to impersonate a Domain Controller, potentially leading to complete control over an Active Directory domain.

Understanding Certighost and Its Impact

The Certighost vulnerability was addressed in Microsoft’s July 2026 security updates. This flaw affects Microsoft’s public key infrastructure (PKI), which issues X.509 certificates for encryption, signing, and authentication within domains. These certificates function similarly to digital IDs, with a Certification Authority (CA) authorizing them by linking a public key to a particular identity.

The vulnerability is particularly critical in scenarios involving certificate-based Kerberos authentication (PKINIT). Here, the flaw disrupts the correlation between a certificate and its associated AD account, due to issues in the mapping process performed by the Key Distribution Center (KDC).

Technical Details of the Vulnerability

Certighost exploits a specific aspect of the CA’s operations: a secondary directory inquiry known as a chase. This process is influenced by two attributes: cdc (Client DC) and rmd (Remote Domain). The vulnerability arises because the CA does not verify whether the host specified in the cdc attribute is a legitimate Domain Controller.

By setting up malicious SMB, LDAP, and LSA services, attackers can manipulate the CA into accepting false identity data. This includes supplying a real Domain Controller’s Security Identifier (SID) and DNS hostname for the rmd target, thus bypassing normal authentication checks.

Mitigation and Future Outlook

To mitigate the risk, Microsoft introduced a validation function, _ValidateChaseTargetIsDC, in its July patch. This function performs several checks, such as rejecting invalid hostnames and confirming the target’s authenticity as a computer object. Only if these criteria are met does the CA proceed with the chase and issue the certificate.

For organizations unable to immediately apply the July patch, a temporary workaround involves disabling the vulnerable chase feature through a specific command. However, this is not a permanent solution, and organizations are urged to prioritize patching.

A proof-of-concept has been published on GitHub, emphasizing the urgency for enterprises utilizing AD CS to update their systems and audit relevant settings to prevent exploitation.

Strengthening security operations by integrating advanced threat detection tools can further safeguard against such vulnerabilities.

Cyber Security News Tags:Active Directory, AD CS, Certificate Services, Certighost, CVE-2026-54121, cyber attack prevention, Cybersecurity, digital certificates, domain controller, domain security, IT security, Kerberos authentication, Microsoft patch, security update, vulnerability patch

Post navigation

Previous Post: Tego AI Reveals Second Security Issue in Claude Software
Next Post: Critical Bing Images Flaws Patched Amid Security Concerns

Related Posts

1-Click Clawdbot Vulnerability Enable Malicious Remote Code Execution Attacks 1-Click Clawdbot Vulnerability Enable Malicious Remote Code Execution Attacks Cyber Security News
New Android Malware ‘Fantasy Hub’ Intercepts SMS Messages, Contacts and Call Logs New Android Malware ‘Fantasy Hub’ Intercepts SMS Messages, Contacts and Call Logs Cyber Security News
Threat Actors Hijack Popular npm Packages to Steal The Project Maintainers’ npm Tokens Threat Actors Hijack Popular npm Packages to Steal The Project Maintainers’ npm Tokens Cyber Security News
Threat Actors Weaponizing YouTube Video Download Site to Download Proxyware Malware Threat Actors Weaponizing YouTube Video Download Site to Download Proxyware Malware Cyber Security News
Critical Exploits Target Langflow and Ruby on Rails Systems Critical Exploits Target Langflow and Ruby on Rails Systems Cyber Security News
Doctors Imaging Group Suffers Data Breach Doctors Imaging Group Suffers Data Breach Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • OpenAI Pledges $1 Billion for AI Cybersecurity Tools
  • New Linux Malware Tengu Hides as Kernel Process
  • ConnectWise Highlights ScreenConnect Security Issue
  • Microsoft Phasing Out Manifest V2 Extensions by 2027
  • Sensitive Employee Data Breach at Natural Resources Wales

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • OpenAI Pledges $1 Billion for AI Cybersecurity Tools
  • New Linux Malware Tengu Hides as Kernel Process
  • ConnectWise Highlights ScreenConnect Security Issue
  • Microsoft Phasing Out Manifest V2 Extensions by 2027
  • Sensitive Employee Data Breach at Natural Resources Wales

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark