Certighost Flaw Let Ordinary Users Impersonate Domain Controllers and Seize Active Directory
A newly patched Active Directory Certificate Services bug, dubbed Certighost, let any low-privileged domain user trick a certificate authority into treating a rogue machine as a real Domain Controller. From there, attackers could extract the krbtgt hash and take over an entire Windows domain.
Itagora tiene in archivio titolo e sommario per la ricerca interna. Il testo completo resta sulla fonte. Il link in uscita non invia referrer.