Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Certighost Vulnerability Allows Domain Controller Impersonation

Certighost Vulnerability Allows Domain Controller Impersonation

Posted on July 24, 2026 By CWS

Security researchers H0j3n and Aniq Fakhrul have identified a critical vulnerability, named Certighost, which allows low-privileged Active Directory users to impersonate domain controllers. This flaw, published on July 24, 2026, can potentially enable unauthorized access by obtaining a certificate for a Domain Controller, thereby authenticating as that machine. The issue primarily impacts the Active Directory Certificate Services (AD CS) and was assigned CVE-2026-54121 with a CVSS score of 8.8.

Understanding the Vulnerability

Certighost operates by exploiting improper authorization within AD CS, requiring only network access and a basic domain account, without the need for administrative rights or user interaction. In practical tests, even a standard Domain Users account could leverage this flaw by creating or reusing a computer account, subject to the default ms-DS-MachineAccountQuota value of 10. This process necessitates an Enterprise CA that follows the vulnerable chain path for certificate enrollment, along with network connectivity to the attacker’s SMB and LDAP listeners.

Microsoft addressed this vulnerability with a patch released on July 14, 2026. Organizations utilizing Enterprise CA are urged to apply these updates promptly. Although no real-world exploitations have been reported as of July 24, the proof-of-concept is publicly available, raising concerns about potential misuse.

Technical Details and Mitigation Strategies

The flaw resides in an AD CS feature known as a chase fallback, where a certification authority (CA) might not correctly validate the authenticity of a Domain Controller. Researchers demonstrated that a CA could be misled by a rogue Local Security Authority (LSA) and LDAP services, leading to unauthorized certificate signing. Attackers could relay the CA’s authentication challenge to a genuine Domain Controller through Netlogon, ultimately compromising its identity.

To mitigate this risk temporarily, administrators can disable the chase fallback, though this might disrupt legitimate certificate enrollments. The recommended command to implement this workaround is:

certutil -setreg policyEditFlags -EDITF_ENABLECHASECLIENTDC
Restart-Service CertSvc -Force

Patch Implementation and Future Outlook

Microsoft’s patch introduces a validation step within certpdef.dll, ensuring that only legitimate domain controllers are followed during the chase. This update restricts IP literals, overly long names, and LDAP metacharacters, while requiring a specific Active Directory computer object match.

The vulnerability affects a range of systems, including Windows Server editions from 2012 to 2025 and certain Windows 10 versions. Security teams should prioritize patching and consider the temporary workaround where immediate updates are not feasible.

The Certighost vulnerability underscores the need for robust security practices and timely updates. Organizations should remain vigilant, continuously evaluating their security posture to prevent unauthorized access and data breaches.

The Hacker News Tags:Active Directory, Certificate Services, Certighost, CVE-2026-54121, domain controller, enterprise security, Exploit, Kerberos, Microsoft, Patch, Security, Vulnerability

Post navigation

Previous Post: Malicious Bing Ads Exploit AI Interests to Spread Malware
Next Post: ChonkyChicken Malware Targets Chrome Credentials

Related Posts

Intellexa Leaks Reveal Zero-Days and Ads-Based Vector for Predator Spyware Delivery Intellexa Leaks Reveal Zero-Days and Ads-Based Vector for Predator Spyware Delivery The Hacker News
Meta’s AI Tool Utilizes Public Instagram for Image Creation Meta’s AI Tool Utilizes Public Instagram for Image Creation The Hacker News
5 Ways Identity-based Attacks Are Breaching Retail 5 Ways Identity-based Attacks Are Breaching Retail The Hacker News
Hackers Deploy Stealth Backdoor in WordPress Mu-Plugins to Maintain Admin Access Hackers Deploy Stealth Backdoor in WordPress Mu-Plugins to Maintain Admin Access The Hacker News
SloppyLemming Uses New Malware Chains on South Asian Governments SloppyLemming Uses New Malware Chains on South Asian Governments The Hacker News
Russia-Aligned Hackers Abuse Viber to Target Ukrainian Military and Government Russia-Aligned Hackers Abuse Viber to Target Ukrainian Military and Government The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Cl0p Hackers Target Windchill Servers for Data Theft
  • BlueNoroff Targets Crypto Wallets via Phishing on Zoom
  • ChonkyChicken Malware Targets Chrome Credentials
  • Certighost Vulnerability Allows Domain Controller Impersonation
  • Malicious Bing Ads Exploit AI Interests to Spread Malware

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Cl0p Hackers Target Windchill Servers for Data Theft
  • BlueNoroff Targets Crypto Wallets via Phishing on Zoom
  • ChonkyChicken Malware Targets Chrome Credentials
  • Certighost Vulnerability Allows Domain Controller Impersonation
  • Malicious Bing Ads Exploit AI Interests to Spread Malware

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark