Skip to content

Certificate PrivEsc

Certificate-Based Privilege Escalation in Active Directory leverages misconfigurations in certificate infrastructure to elevate privileges. Attackers often exploit certificate-based authentication mechanisms, such as Kerberos delegation or certificate impersonation, to gain unauthorized access to sensitive resources. This section explores advanced techniques for exploiting certificate-based vulnerabilities in AD environments.


Kerberos Delegation and Certificate Impersonation

Kerberos delegation allows services to act on behalf of users, but misconfigured permissions can enable attackers to impersonate service accounts using certificates. For example, if a user has access to a certificate issued to a privileged service (e.g., krbtgt), they can use it to forge Kerberos tickets and escalate privileges.

Example: Requesting a Certificate via Certipy

certipy request -dc-ip <DC_IP> -target <DOMAIN> -username <USER> -password <PASS> -template <TEMPLATE_NAME>
Replace <TEMPLATE_NAME> with a certificate template that grants elevated privileges (e.g., UserAccountControl-Admin).

Example: Using the Certificate for Impersonation

certipy dump -dc-ip <DC_IP> -target <DOMAIN> -username <USER> -password <PASS> -certificate <CERT_FILE>
This extracts the certificate, which can then be used with tools like kerberos or mimikatz to forge tickets.


Exploiting Certificate Revocation Lists (CRLs)

Certificate revocation lists (CRLs) are used to invalidate compromised certificates. Attackers may exploit CRL bypasses or incomplete revocation checks to reuse revoked certificates. For instance, if a certificate is revoked but not properly checked during authentication, it can be used for privilege escalation.

Example: Checking CRL Status

certutil -viewstore -user -v
This command displays the certificate store, allowing you to verify if revoked certificates are still present in the trust chain.

Example: Bypassing CRL Checks
Attackers may use tools like certutil to manually update the CRL cache or manipulate the CRLDistributionPoints extension in a certificate to point to a malicious server.


Certipy for Certificate-Based Attacks

Certipy is a powerful tool for interacting with AD CS and managing certificates. It can be used to request, dump, and exploit certificates for privilege escalation.

Example: Enumerating Certificate Templates

certipy enumerate -dc-ip <DC_IP> -target <DOMAIN> -username <USER> -password <PASS>
This lists available certificate templates, helping identify templates with elevated permissions.

Example: Requesting a Certificate with Specific Permissions

certipy request -dc-ip <DC_IP> -target <DOMAIN> -username <USER> -password <PASS> -template "UserAccountControl-Admin"
Requests a certificate with administrative privileges, assuming the user has access to the CA.


Key takeaways

  • Kerberos delegation can be exploited if a user has access to a privileged certificate.
  • CRL bypasses allow attackers to reuse revoked certificates if revocation checks are incomplete.
  • Certipy is essential for requesting, dumping, and exploiting certificates in AD environments.
  • Always verify certificate templates and revocation policies to identify potential misconfigurations.