YouTube Video
🔗 Register for this FREE Infosec webcast and more! –
https://poweredbybhis.com
Active Directory Certificate Services misconfigurations continue to give attackers powerful privilege escalation paths, sometimes allowing low privileged accounts to reach Domain Administrator. Hardening efforts often focus on removing dangerous EKUs such as Client Authentication from certificate templates, but Server Authentication is frequently left behind.
Join Alyssa Snow and Kaitlyn Wimberley, Security Consultants at Black Hills Information Security, for a free one-hour webcast exploring ESC17, a newly documented ADCS escalation technique.
ESC1 taught us that Enrollee-Supplied Subject on a misconfigured template could lead directly to domain compromise. ESC17 demonstrates that the same primitive creates an entirely different attack path when paired with the Server Authentication EKU. Users with enrollment rights can obtain legitimately issued, domain-trusted TLS certificates for arbitrary internal hostnames (including critical infrastructure such as a WSUS server) and impersonate TLS-protected services provided by those hosts.
We’ll walk through a complete attack chain from a low privileged domain user to SYSTEM level execution on targeted domain-joined workstations. No initial administrative privileges. No software vulnerability required. Just a misconfigured template, a trusted certificate, redirected traffic, and an update that definitely came from Microsoft.
Chat with your fellow attendees in the Black Hills Infosec Discord server:
https://discord.gg/BHIS
in the #🔴live-event-chat channel.
https://poweredbybhis.com
Active Directory Certificate Services misconfigurations continue to give attackers powerful privilege escalation paths, sometimes allowing low privileged accounts to reach Domain Administrator. Hardening efforts often focus on removing dangerous EKUs such as Client Authentication from certificate templates, but Server Authentication is frequently left behind.
Join Alyssa Snow and Kaitlyn Wimberley, Security Consultants at Black Hills Information Security, for a free one-hour webcast exploring ESC17, a newly documented ADCS escalation technique.
ESC1 taught us that Enrollee-Supplied Subject on a misconfigured template could lead directly to domain compromise. ESC17 demonstrates that the same primitive creates an entirely different attack path when paired with the Server Authentication EKU. Users with enrollment rights can obtain legitimately issued, domain-trusted TLS certificates for arbitrary internal hostnames (including critical infrastructure such as a WSUS server) and impersonate TLS-protected services provided by those hosts.
We’ll walk through a complete attack chain from a low privileged domain user to SYSTEM level execution on targeted domain-joined workstations. No initial administrative privileges. No software vulnerability required. Just a misconfigured template, a trusted certificate, redirected traffic, and an update that definitely came from Microsoft.
Chat with your fellow attendees in the Black Hills Infosec Discord server:
https://discord.gg/BHIS
in the #🔴live-event-chat channel.