# CVE-2026-54121 ("Certighost"): Low-Privileged AD CS Enrollment Flaw Enables Domain Controller Impersonation

> CVE-2026-54121 ("Certighost") is a CVSS 8.8 improper-authorization flaw in Active Directory Certificate Services (AD CS) that lets any authenticated low-privileged domain user relay a Certification Authority's "chase" fallback resolution to impersonate a Domain Controller, obtain a DC-identity certificate, authenticate via PKINIT, and perform DCSync against krbtgt. Microsoft patched it July 14, 2026 (Patch Tuesday); a working public PoC ("certighost.py") was released July 24, 2026 by researchers H0j3n and Aniq Fakhrul.

- **Published:** 2026-07-24T00:00:00Z
- **Last reviewed:** 2026-10-01T07:04:37.845Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1675
- **ID:** TL-2026-1675
- **Severity:** CRITICAL (CVSS 8.8)
- **Category:** VULNERABILITY
- **Status:** PATCHED
- **Detections:** 9 · **IOCs:** 43 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2026-54121

## Description

AD CS Enterprise Certification Authorities support a certificate-enrollment fallback path called a "chase": when the CA cannot directly resolve the identity of the end entity requesting a certificate, the enrollment protocol allows the requester to supply a `cdc` parameter (an Active Directory server/contact point) and an `rmd` parameter (the machine object to resolve) so the CA can go fetch the missing identity attributes itself. Prior to the July 2026 patch, the CA followed the requester-supplied `cdc` host over SMB and LDAP without first proving that host was a genuine Domain Controller.

An attacker holding nothing more than a standard domain account (or a computer account created under the default `ms-DS-MachineAccountQuota` of 10) can stand up rogue SMB (445) and LDAP (389) listener services, submit a certificate enrollment request whose `cdc` attribute points at the attacker's own host and whose `rmd` attribute names the real target Domain Controller, and let the CA's outbound Netlogon authentication challenge be relayed back to the legitimate DC. The rogue listeners respond with the target DC's `objectSid`, `sAMAccountName`, and `dNSHostName`, which the CA then binds into the issued certificate — producing a valid certificate that asserts the *attacker* is the Domain Controller.

That certificate is used to perform PKINIT Kerberos pre-authentication, yielding a TGT (and derivable NT hash / `.ccache`) for the DC's own machine account. Domain Controller machine accounts hold directory-replication rights (`Replicating Directory Changes` / `Replicating Directory Changes All`), so the attacker can immediately run DCSync to extract the `krbtgt` secret and every domain account credential — full domain compromise from a single unprivileged starting foothold, no admin rights and no user interaction required at any step.

Microsoft's July 14, 2026 update closes the gap by adding `CRequestInstance::_ValidateChaseTargetIsDC` to `certpdef.dll`, which rejects IP literals and over-long names, blocks LDAP metacharacters, requires exactly one matching AD computer object, validates DNS-name correspondence, confirms `userAccountControl` contains `SERVER_TRUST_ACCOUNT` (0x2000), and performs a SID comparison before honoring a chase target as a genuine DC.

A fully automated public exploitation tool (`certighost.py`, github.com/aniqfakhrul/CVE-2026-54121) was released July 24, 2026, ten days after the patch, that creates/reuses a rogue computer account, spins up the SMB/LDAP listeners, drives the enrollment/relay flow end-to-end, and drops a `.pfx` certificate plus a `.ccache` ready for immediate Kerberos-based domain impersonation. No confirmed in-the-wild exploitation had been reported as of the July 24, 2026 disclosure, but the combination of a trivial privilege bar (any domain account), zero user interaction, network-only attack vector, and a fully weaponized public PoC makes unpatched AD CS environments an urgent detection and patching priority.

## MITRE ATT&CK

- T1589 Gather Victim Identity Information
- T1590.001 Gather Victim Network Information: Domain Properties
- T1588.002 Obtain Capabilities: Tool
- T1078.002 Valid Accounts: Domain Accounts
- T1059.006 Command and Scripting Interpreter: Python
- T1136.002 Create Account: Domain Account
- T1649 Steal or Forge Authentication Certificates
- T1098 Account Manipulation
- T1036 Masquerading
- T1187 Forced Authentication
- T1557.001 Name Resolution Poisoning and SMB Relay
- T1003.006 OS Credential Dumping: DCSync
- T1558 Steal or Forge Kerberos Tickets
- T1018 Remote System Discovery
- T1087.002 Account Discovery: Domain Account
- T1550.003 Use Alternate Authentication Material: Pass the Ticket
- T1531 Account Access Removal
- T1068 Exploitation for Privilege Escalation
- T1207 Rogue Domain Controller
- T1552 Unsecured Credentials
- T1210 Exploitation of Remote Services
- T1590 Gather Victim Network Information
- T1595.002 Active Scanning: Vulnerability Scanning
- T1592.002 Gather Victim Host Information: Software
- T1587.001 Develop Capabilities: Malware
- T1212 Exploitation for Credential Access
- T1558.001 Steal or Forge Kerberos Tickets: Golden Ticket
- T1587.004 Develop Capabilities: Exploits

## Sources

- [Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller](https://thehackernews.com/2026/07/certighost-exploit-lets-low-privileged.html)
- [GitHub - aniqfakhrul/CVE-2026-54121: Certighost POC](https://github.com/aniqfakhrul/CVE-2026-54121)
- [Microsoft Security Update Guide - CVE-2026-54121](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54121)
- [NVD Vulnerability Record - CVE-2026-54121](https://nvd.nist.gov/vuln/detail/CVE-2026-54121)
- [CISA Known Exploited Vulnerabilities Catalog](https://www.cisa.gov/known-exploited-vulnerabilities-catalog)
- [Zero Day Initiative — The July 2026 Security Update Review](https://www.thezdi.com/blog/2026/7/14/the-july-2026-security-update-review)
- [Microsoft's July 2026 Update Fixes Active Directory Certificate Services Flaw That Allows Remote Takeover](https://windowsnews.ai/article/microsofts-july-2026-update-fixes-active-directory-certificate-services-flaw-that-allows-remote-take.438636)
- [Certighost technical analysis gist (H0j3n)](https://gist.github.com/H0j3n/a5ef2609b5f2944ac2390a191a534c26)
- [Certipy — AD CS attack/audit framework (referenced tooling)](https://github.com/ly4k/Certipy)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1675
