A vulnerability in Active Directory Certificate Services (CVE-2026-54121) allows a low-privileged domain user to impersonate a Domain Controller and achieve domain compromise by manipulating the chase fallback enrollment behavior. The flaw occurs when the Certification Authority (CA) accepts a requester-supplied chase target without first verifying its authenticity, enabling an attacker to direct the CA to their controlled host and return directory data for a chosen target principal. This can influence certificate identity material issued by the CA, including strong-mapping SID and DNS identity fields used during authentication. The vulnerability has significant business impact as it allows an attacker to compromise domain security and potentially gain unauthorized access to sensitive information. The issue was addressed in the July 2026 security updates, which changed the CA-side request path to prevent this type of attack. This flaw is related to the chase fallback enrollment behavior in AD CS, where the CA contacts a host named by cdc over SMB and LDAP, then searches for a principal named by rmd. An attacker can supply request attributes such as cdc and rmd in a certificate request, causing the CA to open connections to an attacker-controlled host and use returned identity data while building the certificate. The vulnerability is categorized as a flaw type and has a CVSS score of 8.5 (High) with an attack vector of Network.
We recommend you to update with Microsoft’s July 2026 updates or latest.[/subscribe_to_unlock_form]
A vulnerability in Active Directory Certificate Services (CVE-2026-54121) allows a low-privileged domain user to impersonate a Domain Controller and achieve domain compromise by manipulating the chase fallback enrollment behavior. The flaw occurs when the Certification Authority (CA) accepts a requester-supplied chase target without first verifying its authenticity, enabling an attacker to direct the CA to their controlled host and return directory data for a chosen target principal. This can influence certificate identity material issued by the CA, including strong-mapping SID and DNS identity fields used during authentication. The vulnerability has significant business impact as it allows an attacker to compromise domain security and potentially gain unauthorized access to sensitive information. The issue was addressed in the July 2026 security updates, which changed the CA-side request path to prevent this type of attack. This flaw is related to the chase fallback enrollment behavior in AD CS, where the CA contacts a host named by cdc over SMB and LDAP, then searches for a principal named by rmd. An attacker can supply request attributes such as cdc and rmd in a certificate request, causing the CA to open connections to an attacker-controlled host and use returned identity data while building the certificate. The vulnerability is categorized as a flaw type and has a CVSS score of 8.5 (High) with an attack vector of Network.
We recommend you to update with Microsoft’s July 2026 updates or latest.[emaillocker id="1283"]
The following reports contain further technical details:
[/emaillocker]