Skip to content
REDMAW

Internal Infrastructure

ADCS Certificate Abuse

Weak certificate-template or enrollment configuration can turn AD Certificate Services into a route for impersonation or privilege escalation.

RedMaw

Definition

Active Directory Certificate Services issues certificates according to templates. Where a template's enrollment permissions and subject rules are too permissive, a low-privileged requester may be able to obtain a certificate that authenticates as somebody else.

Why it is unusually durable

An issued certificate is valid for its lifetime. Resetting the impersonated account's password does not invalidate it. Containment requires revocation and an understanding of what was issued, which is precisely the kind of record that is rarely reviewed until it matters.

What to review

  • Which principals may enroll against which templates
  • Whether a requester can influence the subject identity
  • Whether issuance requires approval
  • Which templates permit client authentication
  • Whether issued certificates are inventoried at all
Where it leads
  1. Internal Identity
  2. Certificate Enrollment
  3. Abusable Certificate
  4. Privileged Identity
  5. Critical System

Each hop validated by successful exploitation

Tags

  • adcs
  • pki
  • privilege escalation

Validation

How RedMaw validates this attack

Validation runs only inside authorized scope, with agreed exploitation limits.

  1. 01Enumerate certificate templates and enrollment permissions
  2. 02Identify templates permitting requester-influenced subjects
  3. 03Establish which identities could be impersonated
  4. 04Report the template configuration and its privilege consequence

Stop assuming you are secure. Prove it.

Continuously test what an attacker can actually reach across your applications, SaaS identities, internal infrastructure and AI systems.