Certighost (CVE-2026-54121) — Impersonating a Domain Controller via AD CS
Attack Techniques & Methods2026-08-06, 13:03
This article describes the exploitation of the vulnerability CVE-2026-54121. A low-privileged domain user can impersonate a domain controller by exploiting the fallback mechanism used when issuing certificates through AD CS. By supplying special request attributes —
cdc (Client DC) and rmd (Remote Domain), the attacker forces the enterprise certification authority (CA) to connect to a host under their control over SMB and LDAP.The CA then blindly trusts the directory objects it receives (
objectSid and dNSHostName of the actual domain controller) and issues a certificate with the correct identity mapping. This allows the attacker to authenticate via PKINIT as the domain controller and effectively obtain its privileges.Vulnerabilities
Products