Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller

Researchers H0j3n and Aniq Fakhrul revealed a working exploit that exploits a vulnerability in Windows Server 2012 R2, allowing a low-privileged Active Directory user to obtain a certificate for a Domain Controller and authenticate as that machine, effectively impersonating it.

On July 24, a proof-of-concept (PoC) exploit was published by H0j3n and Aniq Fakhrul, demonstrating a flaw in Windows Server 2012 R2 that can be exploited by a low-privileged Active Directory user. This vulnerability, known as Certighost, enables the user to obtain a digital certificate for a Domain Controller and subsequently authenticate as that machine. The exploit takes advantage of a weakness in the way Windows Server 2012 R2 handles certificate requests.

Domain Controller accounts carry significant directory replication responsibilities, making them a critical component of an organization's Active Directory infrastructure. By impersonating a Domain Controller, an attacker could potentially access sensitive data, disrupt directory services, or even steal credentials. As a result, this vulnerability has significant implications for organizations that rely on Windows Server 2012 R2.

The researchers' exploit, while not yet widely adopted, highlights the importance of regularly updating and patching software to prevent such vulnerabilities from being exploited. Organizations are advised to prioritize Windows Server 2012 R2 updates and to take proactive measures to secure their Active Directory infrastructure.

Source: The Hacker News