Proof-of-concept exploit released for Certighost Windows AD CS vulnerability

In a significant development for cybersecurity, a proof-of-concept exploit has emerged for a vulnerability in Windows Active Directory Certificate Services (AD CS), referred to as Certighost. This vulnerability, tracked under the identifier CVE-2026-54121, poses a serious risk by potentially enabling authenticated attackers to compromise an entire Windows domain.

Details of the Vulnerability

Microsoft addressed the Certighost vulnerability in its July 2026 security updates. The flaw allows an authenticated attacker to manipulate machine account attributes within the AD CS framework, thereby obtaining a certificate that can be used to authenticate as a targeted machine, including critical domain controllers. This capability opens the door for attackers to impersonate domain controllers and execute privileged Active Directory operations.

The vulnerability was uncovered by researchers H0j3n and Aniq Fakhrul, who not only identified the flaw but also disclosed it publicly alongside a functional exploit. This exploit takes advantage of a fallback mechanism within AD CS, known as a “chase.” In this scenario, an attacker can redirect the Certification Authority (CA) to a rogue server, which then provides misleading information about a machine account. As a result, the attacker can obtain a certificate that confers domain-level administrative privileges.

Implications of the Exploit

The released proof-of-concept automates the exploitation process, allowing attackers to extract sensitive credentials, including the krbtgt account’s NT hash, through a DCSync attack. This development raises significant concerns for organizations relying on Windows Active Directory, as it highlights the potential for severe security breaches if the vulnerability is not adequately addressed.

In response to the threat posed by Certighost, Microsoft has implemented additional validation measures in the chase process, ensuring that the Certification Authority verifies the legitimacy of domain controllers before issuing certificates. This proactive step aims to bolster the security of Active Directory environments and mitigate the risks associated with this vulnerability.

Winsage
Proof-of-concept exploit released for Certighost Windows AD CS vulnerability