Enterprise IT Support β€’ Bangkok & Nationwide

Technology newsroom

🚨 Certighost: A critical vulnerability in Active Directory that allows regular users to take over the Domain Controller!

A critical Certighost vulnerability has been found in Active Directory that allows low-privilege users to elevate their privileges to Domain Controller and steal all passwords in the system through the DCSync technique, leading to the risk of the entire network being compromised.

Edited by SyncTech Solution Published Source Original source
🚨 Certighost: A critical vulnerability in Active Directory that allows regular users to take over the Domain Controller!

πŸ“Œ Summary of important points:
- A new vulnerability named Certighost has been discovered, allowing low-level users in Active Directory to impersonate a Domain Controller.
- Hackers can use the privileges of the Domain Controller to steal all password data in the system through the DCSync technique
- This attack allowed hackers to create Golden Tickets and gain full control over the organization's network.

Security researchers H0j3n and Aniq Fakhrul disclosed code for exploiting a new critical vulnerability on July 24, under the codename Certighost. This vulnerability directly affects the Active Directory (AD) system, which is central to managing users and resources in most organizations' networks.

The threat of Certighost is that it allows ordinary users with very low privileges (Low-Privileged User) to request a certificate to impersonate a Domain Controller (DC), which is essentially the top controller of the network. Once hackers can impersonate a DC, they immediately gain rights to perform Directory Replication.

βš™οΈ Attack Mechanics and Effects
The Directory Replication permission is extremely dangerous because it allows that account to synchronize all data from Active Directory, including the most sensitive information. Hackers use this permission along with a technique called DCSync to extract the password hashes of all accounts in the system, including the password of the secret account krbtgt, which is the account used to generate Kerberos tickets (Kerberos Ticket Granting Ticket).

Once hackers have obtained the secret information of krbtgt, they can create what is called a Golden Ticket. This Golden Ticket is like a master key that allows hackers to access all resources on the network as they wish for a long period of time without being easily detected, and that means they can completely take control of the organization's entire system.

Organizations that use Active Directory should be aware of this risk and closely follow preventive measures or patches from Microsoft, as this vulnerability is considered one of the most concerning avenues that could lead to a full system takeover.

πŸ’¬ Does your organization regularly perform vulnerability checks on Active Directory? Let's share prevention approaches.

Let’s build what’s next

Better IT starts with understanding your business.

Tell our engineers what you need and receive an initial recommendation at no cost.