Critical Privilege Escalation in Microsoft AD Certificate Services (CVE‑2026‑54121) Enables Domain‑Controller Impersonation
What It Is — A flaw in Active Directory Certificate Services (AD CS) allows a low‑privileged domain user to coerce an Enterprise CA into issuing a valid X.509 certificate that impersonates a Domain Controller. The attacker can then use PKINIT to obtain a Domain‑Controller‑level Kerberos ticket and extract credential material, including the KRBTGT hash.
Exploitability — Proof‑of‑concept published 24 Jul 2026; Microsoft released a patch 14 Jul 2026. CVSS v3.1 base score 8.8 (High).
Affected Products — Microsoft Windows Server 2012 R2 and later versions that run Active Directory Certificate Services (AD CS).
Why It Matters for Compliance & Audit Readiness
- Control Mapping: The vulnerability bypasses traditional ACL checks, exposing gaps in your “certificate issuance” control mapping required by SOC 2 CC6.1 (Logical Access Controls).
- Continuous Evidence: Detecting rogue certificates and anomalous CA outbound connections provides audit‑ready evidence that your PKI governance controls are operating effectively.
- Due Diligence: Enterprise buyers increasingly demand proof that PKI components are continuously monitored and that any deviation is logged and remediated, a core tenet of SOC 2 readiness.
Recommended Actions
- Deploy Microsoft’s July 2026 patch on all AD CS servers immediately.
- Harden CA enrollment: disable the “chase” (cdc) functionality or restrict it to trusted endpoints only.
- Implement continuous monitoring for newly issued certificates that contain Domain‑Controller‑level attributes; alert on any such issuance.
- Review and document CA access‑control policies, mapping them to SOC 2 CC6.1 controls and capturing evidence in your Trust Center.
- Conduct a post‑patch validation scan to confirm the vulnerability is mitigated and update your control evidence repository.
Source: BleepingComputer – Certighost and the Privilege Hiding in Your Certificate Authority