Certighost to Domain Takeover: AD CS chase referrals weaponized for Domain Controller impersonation.
← Back to Labs
← Volver a Labs
Medium
CVE
Privilege Escalation
Windows

Certighost to Domain Takeover: AD CS chase referrals weaponized for Domain Controller impersonation.

Certighost (CVE-2026-54121) is a critical improper-authorization vulnerability in Microsoft Active Directory Certificate Services (AD CS) that allows any low-privileged authenticated domain user to impersonate a Domain Controller.

labs correlati

Contacts

Get in touch with us

Contact Us
chevron-right