Back to glossary

AD CS abuse

1 min read

AD CS abuse is the exploitation of misconfigured Active Directory Certificate Services to obtain a certificate that authenticates as another account. Because the directory accepts certificate based logon, a certificate issued for a privileged user is equivalent to that user’s credentials, and it does not change when their password does.

July 29, 2026
Compartir:

The most common variant is a certificate template that combines three properties: it allows the requester to supply the subject alternative name, it includes an extended key usage that permits client authentication, and it can be enrolled by ordinary domain users. An attacker with any domain account requests a certificate naming a domain administrator, the certification authority issues it, and the attacker authenticates as that administrator. There is no exploit and no unpatched software involved; the request is legitimate and the template said yes.

Other variants attack the surrounding machinery rather than the template: enrolment endpoints that accept relayed authentication, agents permitted to enrol on behalf of others, and weak access control on the certification authority itself, which allows templates to be modified into the state above.

This has become one of the shortest routes to domain administrator on recent internal engagements, and the research that named the configurations is public, which means both sides have the same map. The reason it survives is that the certification authority is usually owned by a team that considers itself outside Active Directory security, and template changes are made for an application project. Evidence in a report is the template name, the specific property that permits the abuse, and the identity we obtained, alongside the wider public key infrastructure review that belongs to the internal testing where certificate templates are enumerated as a matter of routine.

¿Quieres ver cómo trabajamos en Asperis Security?

Agenda 30 minutos con uno de nuestros especialistas. Revisamos tu stack y te decimos qué conviene probar primero.