Kryptovalutaticker:
sysadmin från Cyber Security News

Certighost Active Directory CS Exploit Allows Low-Privileged Users to Compromise Domain

Guru Baran
6 hours ago
7 Visningar
0 Kommentarer
Certighost Active Directory CS Exploit Allows Low-Privileged Users to Compromise Domain

A newly disclosed Active Directory Certificate Services (AD CS) vulnerability, dubbed Certighost, allowed a low-privilege domain user to impersonate a Domain Controller and take over an entire Active Directory domain. Tracked as CVE-2026-54121, the flaw was patched in Microsoft’s July 2026 security updates following responsible disclosure earlier this year. AD CS is Microsoft’s public key infrastructure (PKI) system, issuing X.509 certificates used for encryption, signing, and authentication across a domain. Certificates act like digital ID cards: a Certification Authority (CA) signs them, binding a public key to an identity that other services can trust. One key use case is certificate-based Kerberos authentication...

Läs hela artikeln hos källan.

Delta i diskussionen — kommentera, rösta och dela länkar.

Registrera
Var detta hjälpsamt?
Dela:

Kommentarer (0)

Vänligen logga in eller registrera dig för att delta i diskussionen

Inga kommentarer ännu. Bli först med att kommentera!