Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller
A new exploit named Certighost allows low-privileged Active Directory users to impersonate a Domain Controller by obtaining a certificate through a flaw in Active Directory Certificate Services (AD CS). Researchers H0j3n and Aniq Fakhrul disclosed the vulnerability as CVE-2026-54121 on July 24, after Microsoft had issued a patch on July 14. The flaw enables attackers to retrieve sensitive credentials like krbtgt using DCSync, even without admin rights or user interaction. A working proof-of-concept is now publicly available.