‘CertiHost’ Vulnerability Enables Privilege Escalation in Microsoft Active Directory Certificate Services
What Happened — Microsoft released an emergency update for a high‑severity flaw in Active Directory Certificate Services (AD CS) known as “CertiHost” (CVE‑2024‑21569). The vulnerability allowed an unauthenticated attacker to forge a certificate, then use it to elevate privileges to Domain Administrator and take full control of an AD environment.
Why It Matters for Compliance & Audit Readiness
- The scenario maps directly to SOC 2 CC6.1 (Logical Access Controls) and CC6.2 (Privilege Management) – controls that must be demonstrably enforced and continuously monitored.
- Evidence of timely patching and configuration validation becomes critical audit artefacts; Verisq’s Control Mapping capability can auto‑correlate the patch‑status of AD CS with the relevant SOC 2 controls, giving you a defensible audit trail.
Who Is Affected — Any organization that runs on‑premises Active Directory with AD CS enabled – spanning finance, healthcare, government, SaaS providers, and manufacturing.
Recommended Actions
- Deploy Microsoft’s September 2024 security update for AD CS immediately.
- Conduct a post‑patch validation of AD CS configuration (certificate templates, enrollment permissions).
- Map the patch‑deployment and configuration checks to SOC 2 Access Control and Change Management controls; capture screenshots, logs, and patch‑management tickets as audit evidence.
Source: Dark Reading – CertiHost Flaw Haunts Microsoft Active Directory Certificates
Technical Notes
- CVE‑2024‑21569 (CertiHost) – CVSS 9.8 Critical.
- Exploits a flaw in the certificate‑request handling code of AD CS, enabling forged certificates that bypass authentication.
- Attack vector: remote code execution via crafted certificate enrollment request; requires network access to the AD CS server.