An Active Directory vulnerability codenamed Certighost allows any low-privileged domain user to impersonate a domain controller, effectively granting attackers the ability to forge authentication tokens across an entire enterprise network.
The flaw resides in how Active Directory Certificate Services handles certificate requests. A standard user without administrative rights can exploit the bug to escalate privileges to domain-admin level, bypassing existing security controls.
Microsoft has released a security update addressing the vulnerability. Security researchers who discovered the flaw recommend prioritizing the patch given the ease of exploitation and the scale of potential damage — a single compromised user account can lead to full domain compromise.
Organizations running Active Directory with Certificate Services enabled are urged to apply the patch immediately and audit certificate issuance logs for signs of exploitation.
