Fixing ESC4 - User has dangerous permissions
projectblack.io | research | #remediation | #active-directory | #hardening | #adcs | #esc4 | #certificate-template
Summary
Fixing ESC4: when low-privileged principals hold Owner, Full Control, or Write permissions on an ADCS certificate template they can hijack it to escalate privileges. The fix is removing those ACLs.
- Published
- Collected
Skip to content