Several AD CS escalations are not about a standing misconfiguration but about write access to the objects that control certification. A permission over a template, a CA object, or a CA role lets you create the vulnerable condition yourself, then enrol. These are the paths BloodHound surfaces as writable AD CS objects.
ESC4: writable template#
If you have write access (GenericWrite, GenericAll, WriteDacl, WriteOwner) over a certificate template object, you can rewrite its settings to make it ESC1-vulnerable: enable enrollee-supplied subject, add a client-auth EKU, and grant yourself enrolment. Then enrol as a Domain Admin and, ideally, revert the template:
# Certipy can reconfigure a template to be vulnerable, enrol, and restore it
certipy template -u user@example.local -p pass -template <template> -write-default-configuration
# ... enrol with -upn administrator@example.local, then restore the saved config
ESC5: control of CA objects or the CA host#
ESC5 is the broad category of controlling objects the PKI depends on, outside the templates themselves:
- The CA computer object or the CA server host (local admin on the CA lets you read its private key and issue arbitrary certificates).
- The CA's AD objects (the
pKIEnrollmentService/certificationAuthorityobjects, the PKI containers). - The NTAuthCertificates object, which lists CAs trusted for authentication; writing it can add a rogue CA to the forest's trust.
Control of any of these is equivalent to control of certificate issuance, so it is treated as a domain-escalation primitive.
ESC7: CA role rights#
The CA itself has two powerful roles whose rights can be delegated:
- ManageCA (CA administrator): can change CA configuration, including setting the
EDITF_ATTRIBUTESUBJECTALTNAME2flag that enables ESC6, and can enable certificate-manager approvals. - ManageCertificates (certificate manager): can approve pending requests, so a request that would be held for approval can be approved by the same attacker.
Holding both (or ManageCA to grant yourself ManageCertificates) lets you submit a request for a privileged identity and approve it:
# Certipy: use ManageCA/ManageCertificates to issue despite restrictions
certipy ca -u user@example.local -p pass -ca <ca> -add-officer user # grant cert-manager
certipy req ... -template <template> # submit
certipy ca -u user@example.local -p pass -ca <ca> -issue-request <id> # approve
Exploitation notes#
- ESC4 is the cleanest: one writable template becomes ESC1, so hunt for write access over templates during ACL enumeration.
- ESC7's ManageCA path can also enable the web enrolment endpoint, opening the door to ESC8 relay.
- Always restore a reconfigured template or CA setting afterward to limit disruption and keep the change inconspicuous.
Tools#
- Certipy (
template,ca): reconfigure templates, manage CA roles, approve requests. - PSPKI / Certify: Windows-side CA and template management.
References#
- SpecterOps: Certified Pre-Owned (ESC4, ESC5, ESC7)
- The Hacker Recipes: AD CS access control