Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Certighost Flaw in AD CS Allows Domain Compromise

Certighost Flaw in AD CS Allows Domain Compromise

Posted on July 24, 2026 By CWS

An Active Directory Certificate Services (AD CS) vulnerability known as Certighost, identified as CVE-2026-54121, was recently revealed. This flaw allows low-privilege users to impersonate a Domain Controller, potentially leading to complete control over an Active Directory domain.

Understanding Certighost and Its Impact

The Certighost vulnerability was addressed in Microsoft’s July 2026 security updates. This flaw affects Microsoft’s public key infrastructure (PKI), which issues X.509 certificates for encryption, signing, and authentication within domains. These certificates function similarly to digital IDs, with a Certification Authority (CA) authorizing them by linking a public key to a particular identity.

The vulnerability is particularly critical in scenarios involving certificate-based Kerberos authentication (PKINIT). Here, the flaw disrupts the correlation between a certificate and its associated AD account, due to issues in the mapping process performed by the Key Distribution Center (KDC).

Technical Details of the Vulnerability

Certighost exploits a specific aspect of the CA’s operations: a secondary directory inquiry known as a chase. This process is influenced by two attributes: cdc (Client DC) and rmd (Remote Domain). The vulnerability arises because the CA does not verify whether the host specified in the cdc attribute is a legitimate Domain Controller.

By setting up malicious SMB, LDAP, and LSA services, attackers can manipulate the CA into accepting false identity data. This includes supplying a real Domain Controller’s Security Identifier (SID) and DNS hostname for the rmd target, thus bypassing normal authentication checks.

Mitigation and Future Outlook

To mitigate the risk, Microsoft introduced a validation function, _ValidateChaseTargetIsDC, in its July patch. This function performs several checks, such as rejecting invalid hostnames and confirming the target’s authenticity as a computer object. Only if these criteria are met does the CA proceed with the chase and issue the certificate.

For organizations unable to immediately apply the July patch, a temporary workaround involves disabling the vulnerable chase feature through a specific command. However, this is not a permanent solution, and organizations are urged to prioritize patching.

A proof-of-concept has been published on GitHub, emphasizing the urgency for enterprises utilizing AD CS to update their systems and audit relevant settings to prevent exploitation.

Strengthening security operations by integrating advanced threat detection tools can further safeguard against such vulnerabilities.

Cyber Security News Tags:Active Directory, AD CS, Certificate Services, Certighost, CVE-2026-54121, cyber attack prevention, Cybersecurity, digital certificates, domain controller, domain security, IT security, Kerberos authentication, Microsoft patch, security update, vulnerability patch

Post navigation

Previous Post: Tego AI Reveals Second Security Issue in Claude Software

Related Posts

FBI and Indonesian Police Dismantle Global Phishing Network FBI and Indonesian Police Dismantle Global Phishing Network Cyber Security News
Critical Flaw in Cisco Unified CM Exposes Systems to Exploits Critical Flaw in Cisco Unified CM Exposes Systems to Exploits Cyber Security News
Starbucks Phishing Attack Compromises Employee Data Starbucks Phishing Attack Compromises Employee Data Cyber Security News
CISA Alerts on Active Exploitation of Google Chromium Vulnerability CISA Alerts on Active Exploitation of Google Chromium Vulnerability Cyber Security News
OpenAI’s Limited Release of GPT-5.6 Sol with Security Enhancements OpenAI’s Limited Release of GPT-5.6 Sol with Security Enhancements Cyber Security News
Windows Remote Desktop Gateway UAF Vulnerability Allows Remote Code Execution Windows Remote Desktop Gateway UAF Vulnerability Allows Remote Code Execution Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Certighost Flaw in AD CS Allows Domain Compromise
  • Tego AI Reveals Second Security Issue in Claude Software
  • SourTrade Malvertising Evades Detection with Unique Malware
  • Microsoft Ends Unwanted Ads in Windows 11
  • Golden Chickens Unveils New Malware Threats

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Certighost Flaw in AD CS Allows Domain Compromise
  • Tego AI Reveals Second Security Issue in Claude Software
  • SourTrade Malvertising Evades Detection with Unique Malware
  • Microsoft Ends Unwanted Ads in Windows 11
  • Golden Chickens Unveils New Malware Threats

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark