The CVE identified as CVE-2024-49019, colloquially named “Certighost,” represents a significant risk to organizational identity infrastructure. According to Dark Reading, this high-severity vulnerability allows attackers to achieve Privilege Escalation by exploiting specific behaviors within Microsoft Active Directory Certificate Services (AD CS). By manipulating certificate templates that appear secure but contain underlying configuration flaws, a low-privileged user can potentially gain full control over the entire Active Directory forest.
Technical Analysis of Certighost
AD CS is a server role that allows organizations to build a public key infrastructure (PKI) and provide certificates for various purposes, including code signing, encrypted file systems, and, most critically, network authentication. The security of this system relies heavily on certificate templates, which define the attributes and permissions of the certificates issued.
The technical root of Certighost involves the way AD CS handles template versioning and security descriptors. The vulnerability, discovered by researchers at SpecterOps, highlights a flaw where a template’s settings can be abused if it was created or modified under specific conditions. Specifically, if a certificate template is configured to allow the requester to specify a Subject Alternative Name (SAN), an attacker can request a certificate for a high-privileged account, such as a Domain Administrator, while authenticating as a standard user.
This flaw is particularly dangerous because it bypasses traditional access controls. When a template version is updated, or when certain legacy templates are present in the environment, the system may not correctly enforce the expected security boundaries. This creates a scenario where the TTP used by threat actors involves identifying these “ghost” misconfigurations that remain even after an administrator believes the template has been secured. This technique is recognized within the MITRE ATT&CK framework as Exploitation for Privilege Escalation (T1068).
Detecting and Mitigating Microsoft Active Directory Certificate Services Privilege Escalation
Defenders must prioritize visibility into their PKI environment to identify potential abuse. A primary objective for security teams should be researching how to detect CVE-2024-49019 exploit attempts within their infrastructure. This involves monitoring Windows Event Logs for certificate enrollment activity. Specifically, Event IDs 4886 (Certificate Services received a certificate request) and 4887 (Certificate Services approved a certificate request and issued a certificate) should be scrutinized for anomalies.
If a standard user account requests a certificate based on a template that allows the enrollee to supply the subject name, this should trigger an immediate alert in the SIEM. Advanced SOC teams can also use tools like Certify or PSPKIAudit to enumerate templates that are vulnerable to this specific class of escalation.
Beyond detection, the risk of Lateral Movement following a successful exploit is high. Once an attacker obtains a certificate for a privileged user, they can use it to request Kerberos Ticket Granting Tickets (TGTs), effectively masquerading as that user across the network. This allows them to bypass traditional password-based security measures and move toward sensitive data or domain controllers.
Remediation Steps
To address the Certighost vulnerability, organizations must follow a structured remediation plan:
- Apply Security Updates: Install the November 2024 Microsoft security updates across all domain controllers and AD CS servers. This update introduces more stringent checks on template versioning and enrollment requests.
- Audit Certificate Templates: Identify any templates where the
CT_FLAG_ENROLLEE_SUPPLIES_SUBJECTflag is set. Unless there is a documented and secured business requirement, this configuration should be disabled. - Enforce Strong Mapping: Ensure that certificate mapping to user accounts is strictly enforced and that weak mapping techniques are deprecated in favor of more secure alternatives like SID-based mapping.
- Restrict Enrollment Permissions: Review the Access Control Lists (ACLs) on all certificate templates. Only the minimum necessary users and groups should have ‘Enroll’ or ‘Write’ permissions on any template, especially those used for authentication.