Researchers released a proof-of-concept (PoC) exploit for a now-patched flaw in Microsoft's Active Directory Certificate Services (AD CS) that can allow a low-privileged domain user to impersonate a domain controller and fully compromise an AD environment. The flaw was present due to a defective trust boundary within the certificate-based client authentication aspect of Microsoft AD Services. In its July raft of a record 622 Patch Tuesday updates, Microsoft patched a flaw tracked as CVE-2026-54121, which the researchers who discovered and exploited it — Aniq Fakhrul (@aniqfakhrul) and Muhammad Ali (@h0j3n) — called "Certighost," according to a post by the researchers on GitHub. As the researchers described, the vulnerability affects the enterprise certificate authority's (CA) handling of an AD CS enrollment fallback mechanism known as a "chase," which is a second directory lookup performed in some cross-domain controller enrollment scenarios. Because of the flaw, Fakhrul and Ali found that during the issuance of certificates — which bind a subject to a public key — the CA could be tricked into querying an attacker-controlled host for AD identity information by manipulating the cdc (Client DC) and rmd (Remote Domain) request attributes, they explained. "The vulnerable path is an AD CS enrollment fallback known as a chase during directory-object resolution," the researchers wrote in the post. "By supplying request attributes such as cdc, an attacker could cause the Certificate ...
'Certighost' Flaw Haunts Microsoft Active Directory Certificates
Dark Reading
·Elizabeth Montalbano
·Published Jul 28, 2026
·Updated
Affected Software
1 affected component
Microsoft Active Directory Certificate Services (AD CS)
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a flaw in Microsoft's Active Directory Certificate Services that allows low-privileged users to impersonate domain controllers.
2
What security implications are discussed?
The flaw can lead to full compromise of an Active Directory environment, significantly undermining security.
3
What software is affected by this vulnerability?
The vulnerability affects Microsoft's Active Directory Certificate Services (AD CS).
4
Has this flaw been patched?
Yes, the flaw has been patched following the release of a proof-of-concept exploit.
5
When was the vulnerability first exploited?
The flaw is listed in the Known Exploited Vulnerabilities (KEV) database with an exploitation date of August 6, 2026.