ESC1 Attack Explained
semperis.com | blog | #active-directory | #privilege-escalation | #vulnerability | #defense | #ad-cs | #esc1 | #certificate-templates
Summary
ESC1 abuses AD CS certificate templates with requester-supplied subject names and client-auth EKUs, letting an attacker get a certificate for any account, such as Domain Admin.
- Published
- Collected
Skip to content