Home / Jul 25, 2026 / Story
0
#2 The Hacker News general July 24, 2026 at 14:15 UTC

Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller

By [email protected] (The Hacker News)

AI Summary

Researchers H0j3n and Aniq Fakhrul published a working exploit on July 24 for 'Certighost,' a flaw allowing low-privileged Active Directory users to obtain a Domain Controller certificate and authenticate as that machine account. The resulting Kerberos credential can then perform a DCSync attack to retrieve the krbtgt secret, enabling full domain compromise. This Active Directory privilege escalation path represents a critical risk for enterprise environments running misconfigured AD Certificate Services.

Relevance score: 87.0/100

# More from July 25