Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller
Researchers H0j3n and Aniq Fakhrul published a working exploit that lets a low-privileged Active Directory user obtain a certificate for a Domain Controller and authenticate as that machine. The flaw, codenamed Certighost, was patched by Microsoft ten days earlier as CVE-…
Intelligence analysis by Llama

A low-privileged Active Directory user can obtain a certificate for a Domain Controller and authenticate as that machine using the Certighost exploit. The exploit was patched by Microsoft as CVE-2026-54121.
Imagine you have a special key that lets you unlock a super-secure door. But, what if someone else could make a fake key that looks exactly like the real one? That's basically what the Certighost exploit does - it lets someone else make a fake key that looks like a real Domain Controller's key. This can be very bad because it can let the fake key unlock sensitive secrets.
Analysis
A $60B Vote of Confidence
The Certighost exploit is a significant vulnerability in Active Directory Certificate Services (AD CS) that allows low-privileged users to obtain a certificate for a Domain Controller and authenticate as that machine. This exploit was patched by Microsoft ten days earlier as CVE-2026-54121. The vulnerability is caused by improper authorization in the AD CS enrollment fallback, which allows an attacker to provide a fake Domain Controller's information and obtain a certificate.
Why Cursor?
To exploit this vulnerability, an attacker needs to have network access and a domain account. They can then use the Public Key Cryptography for Initial Authentication in Kerberos (PKINIT) protocol to authenticate as the target Domain Controller. The resulting credential can request account secrets through DCSync, including the krbtgt secret.
The Road Ahead
Organizations running an Enterprise CA should install Microsoft's July 14 updates on AD CS hosts. Administrators who cannot patch immediately can clear the chase flag and restart Certificate Services. However, this mitigation is only tested in a controlled lab and should be staged first. The researchers recommend treating the July update as the permanent fix.
Key points
- The Certighost exploit allows low-privileged users to obtain a certificate for a Domain Controller and authenticate as that machine.
- The exploit was patched by Microsoft ten days earlier as CVE-2026-54121.
- Organizations running an Enterprise CA should install Microsoft's July 14 updates on AD CS hosts.
- Administrators who cannot patch immediately can clear the chase flag and restart Certificate Services.
If this exploit is patched quickly, it's possible that the impact will be limited, and organizations will be able to protect themselves from potential attacks. However, if the patch is delayed, the risk of exploitation increases, and the consequences could be severe.
If the patch is not applied quickly, the Certighost exploit could be used to gain unauthorized access to sensitive account secrets, leading to serious security risks and potential data breaches.



