ADCS - ESC4
Last updated
Last updated
Certificate templates are securable objects in Active Directory, meaning they have a security descriptor that specifies which Active Directory principals have specific permissions over the template.
Find the Vulnerabilities:
Take the ESC4 template and change it to be vulnerable to ESC1 technique by using the genericWrite privilege we got. (we didn’t set the target here as we target the ldap)
Exploit ESC1 on the modified ESC4 template
authentication with the pfx
Rollback the template configuration