Kryptovaluta-ticker:
sysadmin fra Cyber Security News

Certighost Active Directory CS Exploit Allows Low-Privileged Users to Compromise Domain

Guru Baran
6 hours ago
5 Visninger
0 Kommentarer
Certighost Active Directory CS Exploit Allows Low-Privileged Users to Compromise Domain

A newly disclosed Active Directory Certificate Services (AD CS) vulnerability, dubbed Certighost, allowed a low-privilege domain user to impersonate a Domain Controller and take over an entire Active Directory domain. Tracked as CVE-2026-54121, the flaw was patched in Microsoft’s July 2026 security updates following responsible disclosure earlier this year. AD CS is Microsoft’s public key infrastructure (PKI) system, issuing X.509 certificates used for encryption, signing, and authentication across a domain. Certificates act like digital ID cards: a Certification Authority (CA) signs them, binding a public key to an identity that other services can trust. One key use case is certificate-based Kerberos authentication...

Les hele artikkelen hos kilden.

Delta i diskusjonen — kommenter, stem og del lenker.

Registrer
Var dette nyttig?
Del:

Kommentarer (0)

Vennligst logg inn eller registrer deg for å delta i diskusjonen

Ingen kommentarer ennå. Bli den første til å kommentere!