The public release of a functional proof-of-concept (PoC) exploit for the Certighost vulnerability has transformed a theoretical risk into an active threat for organizations using Windows Active Directory Certificate Services (AD CS). Security teams are now urged to treat the public exploit code as an imminent danger, requiring immediate patching and configuration audits.

The PoC demonstrates how a low-privilege authenticated user can chain weaknesses in AD CS to compromise an entire Windows domain. The exploit, detailed in recent reporting by BleepingComputer, targets flaws in certificate template enrollment and the Encrypting File System (EFS) RPC interface. By exploiting these, an attacker can fraudulently obtain a certificate for a domain controller, allowing them to impersonate that machine and seize control of the environment.

At the heart of the issue is CVE-2024-49478, a vulnerability Microsoft addressed in its April 2024 security updates. Despite patches being available for over two years, the emergence of reliable exploit code makes unpatched systems critically vulnerable. Once an attacker gains initial access—often through phishing or credential theft—the Certighost technique allows them to authenticate as the domain controller itself, bypassing standard security monitoring that focuses on other lateral movement techniques.

The attack undermines the core trust model of Active Directory. By leveraging the organization's own legitimate certificate authority, adversaries can forge authentication tokens, create persistent backdoors, and move laterally with stealth. Environments using AD CS for smart-card authentication, code signing, or Wi-Fi access are particularly exposed if certificate templates have overly permissive enrollment rights.

Immediate, three-part mitigation is essential:

  1. Patch Without Delay: Deploy the April 2024 Microsoft security updates to all systems involved in AD CS, including certificate authorities and enrollment servers.
  2. Audit and Restrict Templates: Review certificate templates for overly broad enrollment permissions. Pay special attention to templates that allow standard users to request certificates with elevated privileges, especially those that could be bound to machine accounts of domain controllers.
  3. Enforce Least Privilege: Apply strict controls on who can manage templates and approve certificate requests. Enhanced logging and alerting on unusual certificate enrollment patterns can help detect abuse attempts.

The release of the Certighost PoC serves as a stark reminder that foundational identity infrastructure, if neglected, becomes a high-value target. Organizations must now verify their patch status and harden AD CS configurations. Proactive red-team and blue-team exercises testing certificate-based attack paths are also recommended to validate detection and response capabilities. In an era where identity is the primary security boundary, active oversight of certificate services is no longer optional.


Certighost 漏洞的功能性概念驗證(PoC)漏洞利用程序公開發布,已將理論風險轉化為使用 Windows Active Directory Certificate Services(AD CS)組織的主動威脅。安全團隊現時敦促,必須將公開的漏洞利用代碼視為迫在眉睫的危險,需立即進行補漏及配置審計。

該 PoC 展示了低權限認證用戶如何能連結 AD CS 中的弱點,從而危及整個 Windows 域。據 BleepingComputer 近期報導詳述,此漏洞利用程序針對的是憑證範本註冊及加密文件系統(EFS)RPC 介面中的缺陷。透過利用這些缺陷,攻擊者可詐騙獲取用於網域控制器的憑證,從而得以冒充該機器並奪取環境的控制權。

問題核心是 CVE-2024-49478,這是微軟於 2024 年 4 月安全更新中已修補的漏洞。儘管補丁已發布超過兩年,但可靠漏洞利用代碼的出現,使得未補漏系統面臨嚴重風險。一旦攻擊者取得初始存取權限(通常透過釣魚或憑證盜竊),Certighost 技術便能讓他們以網域控制器本身的身分進行認證,從而繞過專注於其他橫向移動技術的標準安全監控。

此攻擊削弱了 Active Directory 的核心信任模型。透過利用組織自身合法的憑證授權機構,對手能偽造認證權杖、建立持久性後門,並隱蔽地進行橫向移動。若憑證範本的註冊權限過於寬鬆,則使用 AD CS 進行智能卡認證、代碼簽署或 Wi-Fi 存取的環境將特別容易受到攻擊。

即時的三部分緩解措施至關重要:

  1. 立即補漏: 將 2024 年 4 月的微軟安全更新部署到所有涉及 AD CS 的系統,包括憑證授權機構及註冊伺服器。
  2. 審計並限制範本: 審查憑證範本是否存在過於寬泛的註冊權限。特別注意那些允許標準用戶申請具有提升權限之憑證的範本,尤其是那些可能綁定到網域控制器機器帳戶的範本。
  3. 強制最低權限原則: 對誰能管理範本及批准憑證申請實施嚴格控制。加強對異常憑證註冊模式的記錄和警報,有助於偵測濫用企圖。

Certighost PoC 的發布是一個嚴峻提醒:基礎身分基礎設施若遭忽視,將成為高價值目標。組織現時必須核實其補漏狀態並加固 AD CS 配置。亦建議進行主動的紅隊和藍隊演習,測試基於憑證的攻擊路徑,以驗證偵測和應對能力。在身分已成為首要安全邊界的時代,對憑證服務的主動監督不再是可有可無。

新聞來源 / Original News Source