URL has been copied successfully!
Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller
URL has been copied successfully!

Collecting Cyber-News from over 60 sources

Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller

Researchers H0j3n and Aniq Fakhrul published a working exploit on July 24 that lets a low-privileged Active Directory user obtain a certificate for a Domain Controller and authenticate as that machine.They codenamed the flaw Certighost. Because Domain Controller accounts carry directory replication rights, the resulting Kerberos credential can retrieve the krbtgt secret through DCSync.

First seen on thehackernews.com

Jump to article: thehackernews.com/2026/07/certighost-exploit-lets-low-privileged.html

Loading

Share via Email
Share on Facebook
Tweet on X (Twitter)
Share on Whatsapp
Share on LinkedIn
Share on Xing
Copy link