CISA's red team abused a misconfigured AD CS certificate template (ESC1) to escalate privileges, a technique similar to the Certighost exploit, emphasizing the need for proper certificate template hardening.
CISA's red team abused a misconfigured AD CS certificate template (ESC1) to escalate privileges, a technique similar to the Certighost exploit, emphasizing the need for proper certificate template hardening.