CVE Tools
Back to feed
PoC public Windows Active Directory Certificate Services privilege-escalation Microsoft auth-bypass

New Certighost PoC exploit lets attackers hijack Windows domains

BleepingComputer·By Lawrence Abrams··4 min read
CVE Tools coverage

A proof-of-concept exploit has been made public for a critical flaw in Microsoft's Active Directory Certificate Services, allowing attackers to take control of entire Windows domains. The vulnerability, identified as CVE-2026-54121, was addressed in the July 2026 Patch Tuesday updates but remains exploitable due to the newly released code. Researchers H0j3n and Aniq Fakhrul revealed how an authenticated user with minimal privileges could abuse a certificate enrollment mechanism to impersonate a domain controller and execute high-privilege actions. This poses a serious risk to unpatched systems, especially those still running outdated configurations.