New Exploit Turns Microsoft Security Feature Into Domain Hijacking Weapon
By 813 Staff

For years, the conventional wisdom in Windows security has been that domain dominance requires either nation-state resources or a catastrophic zero-day. That assumption just took a serious hit. A new proof-of-concept exploit, dubbed Certighost, is now circulating that allows attackers with surprisingly modest access to hijack entire Windows domains by weaponizing the very certificate services that organizations rely on for authentication. Internal documents circulating among incident response teams suggest the technique is both elegant and devastating.
According to a report from BleepingComputer (@BleepinComputer), published July 27, the Certighost exploit targets the Active Directory Certificate Services (AD CS) component, a feature present in nearly every enterprise Windows deployment. Engineers close to the project say the attack chain begins with a single compromised endpoint—no domain admin credentials required. From there, Certighost abuses a design flaw in how the Certificate Authority validates enrollment requests, allowing the attacker to issue a fraudulent certificate that impersonates a domain controller. Once that certificate is in hand, the attacker can authenticate as any user, including domain administrators, and pivot laterally with impunity.
The rollout of public knowledge about this vulnerability has been anything but smooth. Multiple cybersecurity firms had been quietly tracking the technique for weeks, but the PoC’s release has forced a scramble. The exploit does not require patching a specific CVE; rather, it leverages a configuration loophole that exists in any environment where AD CS is deployed with default or insufficiently hardened settings. This means the attack surface is vast. Any organization running a Certificate Authority—which is most medium-to-large enterprises—is potentially at risk.
Why this matters: this is not a theoretical exercise. The PoC is now public, and threat actors are actively scanning for vulnerable configurations. A domain compromise of this kind effectively hands over the keys to every system, every user account, and every piece of sensitive data in the organization. The remediation is not a simple patch but a re-architecture of certificate issuance policies, which takes time and planning.
What happens next is uncertain. Microsoft has not yet issued an official advisory, and security engineers are waiting to see if the company will release security hardening guidance or update default configurations. For now, organizations should audit their AD CS deployments immediately, restrict enrollment permissions, and monitor for anomalous certificate requests. The clock started ticking the moment that PoC hit the tweet feed.
Source: https://x.com/BleepinComputer/status/2081847265564520644
