Certighost allowed a low-privilege domain user obtain a valid Domain Controller certificate through AD CS. Microsoft patched the issue in the July security updates.
First seen on hackread.com
Jump to article: hackread.com/microsoft-certighost-flaw-domain-controller-impersonation/
![]()

