SECURITY·중요도 9·2026. 07. 24.·The Hacker News

Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller

── KO ──────────────────

Certighost 취약점을 통해 저권한 AD 사용자가 도메인 컨트롤러를 가장할 수 있다.

연구자 H0j3n과 Aniq Fakhrul은 저권한 Active Directory 사용자가 도메인 컨트롤러를 가장할 수 있는 Certighost 취약점을 공개했다. 이 취약점을 이용하여 사용자는 도메인 컨트롤러에 대한 인증을 받을 수 있으며, 이로 인해 Kerberos 자격 증명을 통해 krbtgt 비밀을 조회할 수 있다. 이 발견은 보안 측면에서 심각한 우려를 불러일으킨다.


── EN ──────────────────

The Certighost exploit allows low-privileged AD users to impersonate a Domain Controller.

Researchers H0j3n and Aniq Fakhrul have released an exploit that allows low-privileged Active Directory users to impersonate a Domain Controller. This vulnerability, dubbed Certighost, enables users to obtain a certificate for the Domain Controller and authenticate as that machine. Consequently, this can lead to retrieving the krbtgt secret through DCSync, raising significant security concerns.

원문 보기 →목록으로