Fixing ESC1 - Enrollee supplies subject and template allows client authentication
projectblack.io | research | #cloud | #active-directory | #hardening | #adcs | #certificate-template | #esc1
Summary
ESC1 remediation: vulnerable ADCS templates let low-privileged users request certificates as other accounts, even domain admins; fixes include restricting enrolment or disabling supply-in-request.
- Published
- Collected
Skip to content