Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

Fixing ESC4 - User has dangerous permissions

Summary

Fixing ESC4: when low-privileged principals hold Owner, Full Control, or Write permissions on an ADCS certificate template they can hijack it to escalate privileges. The fix is removing those ACLs.
Published
Collected

original ↗

Related coverage

back