CTD-000143

Dangerous ACLs expose Certificate Templates container

Critical
Active Directory
Credential Access
v15

Signature Identity

CTD-000143
Threat ID
15
Version
IOE
Indicator Type

Threat Description

Non-default principals with elevated permissions on the Certificate Templates container pose a security risk, as this may allow them to escalate privileges and compromise the domain by introducing a malicious Certificate Authority (CA) into the trust hierarchy.

MITRE ATT&CK: Attack Tactics

Credential Access

D3FEND: Defend Tactics

Credential Hardening

Remediation

  1. Open the ADSI Edit tool.
  2. Navigate to the Configuration container > Services > Public Key Services.
  3. Select Certificate Templates.
  4. Right-click to select Properties.
  5. Select the Security tab.
  6. Remove unexpected permissions.

Frequently Asked Questions

What does Dangerous ACLs expose Certificate Templates container mean?

Non-default principals have been granted elevated permissions to the Certificate Templates container in Active Directory. This allows them to modify or delete certificate templates, potentially introducing a malicious Certificate Authority (CA) into the trust hierarchy.

This vulnerability enables non-default principals to introduce a malicious CA, which can lead to privilege escalation and domain compromise. An attacker with elevated permissions on the Certificate Templates container can create or modify certificate templates to issue rogue certificates, bypassing security controls and gaining unauthorized access to sensitive resources through reconnaissance and persistence.

Attackers can use the elevated permissions on the Certificate Templates container to create or modify certificate templates that issue rogue certificates. These certificates can be used to authenticate malicious entities, allowing them to access sensitive resources and escalate privileges.

Cayosoft Guardian continuously monitors the permissions on the Certificate Templates container in Active Directory. When it detects non-default principals with elevated permissions, Guardian flags it as a security issue so administrators can take action to remediate.

Cayosoft Guardian alerts administrators to remove unexpected permissions on the Certificate Templates container, ensuring that only authorized principals have access. This reduces the risk of privilege escalation and domain compromise by preventing malicious entities from issuing rogue certificates.

Stop AD Threats As They Happen

Cayosoft Protector provides continuous monitoring and real-time alerts across your entire Microsoft Identity stack

Classification
Systems
Active Directory
Themes
Privileged Access Management
Attack Tactics
Credential Access
Defend Tactics
Credential Hardening
Indicator Types
IOE
Related Threats
CTD-000139
Kerberos Constrained Delegation: krbtgt Risks
Critical
CTD-000122
Active Directory Schema Update Permission Risks
Critical