CyberSecurity News
Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller
AI summary
Researchers have published a working exploit for a flaw, dubbed Certighost, that allows a low-privileged Active Directory user to obtain a certificate for a Domain Controller and authenticate as that machine. This exploit enables the user to retrieve the krbtgt secret through DCSync, as Domain Controller accounts have directory replication rights. The exploit was made public by researchers H0j3n and Aniq Fakhrul. The resulting Kerberos credential can be used to impersonate the Domain Controller. The vulnerability can be leveraged by low-privileged users, making it a significant concern. The exploit was published on July 24.
This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.

