CTD-000142

Dangerous ACLs expose certificate containers

Critical
Active Directory
Credential Access
v18

Signature Identity

CTD-000142
Threat ID
18
Version
IOE
Indicator Type

Threat Description

Non-default principals with elevated permissions on the NTAuthCertificates container pose a security risk, as this may allow them to escalate privileges and compromise the domain by introducing a malicious Certificate Authority (CA) into the trust hierarchy.

MITRE ATT&CK: Attack Tactics

Credential Access

D3FEND: Defend Tactics

Credential Hardening

Remediation

  1. Open the ADSI Edit tool.
  2. Navigate to the Configuration container > Services > Public Key Services.
  3. Select NTAuthCertificates.
  4. Right-click to select Properties.
  5. Select the Security tab.
  6. Remove unexpected permissions.

Frequently Asked Questions

What does Dangerous ACLs expose certificate containers mean?

Non-default principals have been granted elevated permissions on the NTAuthCertificates container in Active Directory. This allows them to modify or delete certificates stored within, potentially leading to privilege escalation and CA compromise.

This issue is rated critical because it enables attackers to directly compromise the domain by introducing a malicious CA. This can lead to significant operational impact, making it a high-risk issue that requires immediate attention.

Attackers can introduce a malicious CA into the trust hierarchy by modifying or deleting certificates stored within the NTAuthCertificates container. This allows them to gain unauthorized access and potentially escalate privileges, leading to domain compromise.

Cayosoft Guardian continuously monitors the permissions on the NTAuthCertificates container in Active Directory, detecting unexpected changes or additions. When an issue is detected, Guardian flags it as a security issue so administrators can take corrective action.

Cayosoft Guardian alerts administrators to remove unexpected permissions on the NTAuthCertificates container, providing visibility and supporting investigation into potential attacker activity. This helps prevent attackers from introducing a malicious CA and reduces the risk of privilege escalation and domain compromise.

Stop AD Threats As They Happen

Cayosoft Protector provides continuous monitoring and real-time alerts across your entire Microsoft Identity stack

Classification
Systems
Active Directory
Themes
Privileged Access Management
Attack Tactics
Credential Access
Defend Tactics
Credential Hardening
Indicator Types
IOE
Related Threats
CTD-000139
Kerberos Constrained Delegation: krbtgt Risks
Critical
CTD-000122
Active Directory Schema Update Permission Risks
Critical