Particle.news

Public Proof‑of‑Concept Released for Certighost AD CS Flaw

Publication of a public proof-of-concept raises immediate risk to unpatched AD CS hosts, requiring urgent patching or a temporary disable of the CA’s chase fallback.

Overview

  • Researchers who reported CVE-2026-54121 have published a working proof-of-concept that automates a chase-based attack against Active Directory Certificate Services.
  • Microsoft issued fixes for the flaw in its July 14, 2026 security updates that add checks to verify chase hostnames and SIDs before the CA follows a requester-supplied chase target.
  • The vulnerability lets any authenticated domain user with network access request a CA-signed machine certificate that can authenticate as a target machine or Domain Controller via PKINIT.
  • With a forged DC certificate an attacker can obtain Kerberos credentials, run a DCSync to extract the krbtgt secret, and escalate a low-privilege account to full domain compromise.
  • Administrators should install the July 14 updates on every issuing AD CS server as a priority; if immediate patching is not possible, the optional chase fallback can be disabled via the documented registry/policy change as a temporary mitigation.