Microsoft Fixes Certighost Flaw That Allowed Domain Controller Impersonation
Microsoft has patched a high-severity vulnerability in Active Directory Certificate Services that allowed a user with basic domain access to obtain a valid certificate identifying them as a Domain Controller.
Tracked as CVE-2026-54121 and named Certighost, the flaw received a CVSS score of 8.8. Researchers H0j3n and Aniq Fakhrul reported it to Microsoft in May 2026, and the company released a fix on July 14, 2026. Full technical details and a working proof of concept followed ten days later.
Active Directory Certificate Services, commonly called AD CS, issues certificates that act as trusted digital identities inside company networks. Computers and users can present these certificates when requesting access to services, including Kerberos authentication.
Certificate Authority Trusted the Wrong Server
Certighost affects a fallback process called a “chase.” When a Certification Authority cannot resolve identity information during enrollment, it may contact another directory server to complete the lookup.
A...
Copyright of this story solely belongs to hackread.com. To see the full text click HERE