Threat Advisory

Microsoft Windows Vulnerability Enables Elevation

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT, Critical Infrastructure
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

CVE-2026-54121 with a CVSS score of 8.8 is a vulnerability in Microsoft Windows, specifically affecting Active Directory Certificate Services (AD CS) in various versions, including Windows 10 Version 1607, with impacted versions including 10.0.14393.0, 10.0.17763.0, 6.2.9200.0, 6.3.9600.0, 10.0.20348.0, and 10.0.26100.0. This vulnerability allows a low-privileged domain user to impersonate a Domain Controller, enabling them to gain elevated privileges and potentially compromise the entire domain. An attacker can exploit this vulnerability by standing up rogue LDAP and LSA services, pointing the CA at them, and answering its lookups, which requires access to the default ms-DS-MachineAccountQuota setting that lets them create a machine account. Once exploited, the attacker gains the capability to issue certificates that carry a Domain Controller identity, effectively giving them a master key to the domain. The business impact and consequences of this vulnerability are severe, as it could lead to domain compromise and unauthorized access to sensitive resources. The prerequisites for exploitation include the ability to create a machine account and manipulate the CA into issuing a certificate with a Domain Controller identity, which can be achieved by exploiting the improper authorization flaw in the AD CS role, classified as CWE-285.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

CVE-2026-54121 with a CVSS score of 8.8 is a vulnerability in Microsoft Windows, specifically affecting Active Directory Certificate Services (AD CS) in various versions, including Windows 10 Version 1607, with impacted versions including 10.0.14393.0, 10.0.17763.0, 6.2.9200.0, 6.3.9600.0, 10.0.20348.0, and 10.0.26100.0. This vulnerability allows a low-privileged domain user to impersonate a Domain Controller, enabling them to gain elevated privileges and potentially compromise the entire domain. An attacker can exploit this vulnerability by standing up rogue LDAP and LSA services, pointing the CA at them, and answering its lookups, which requires access to the default ms-DS-MachineAccountQuota setting that lets them create a machine account. Once exploited, the attacker gains the capability to issue certificates that carry a Domain Controller identity, effectively giving them a master key to the domain. The business impact and consequences of this vulnerability are severe, as it could lead to domain compromise and unauthorized access to sensitive resources. The prerequisites for exploitation include the ability to create a machine account and manipulate the CA into issuing a certificate with a Domain Controller identity, which can be achieved by exploiting the improper authorization flaw in the AD CS role, classified as CWE-285.[emaillocker id="1283"]

RECOMMENDATION:

  • We recommend you to update Microsoft Windows 10 to version 10.0.17763.9020.
  • We recommend you to update Microsoft Windows Server to version 6.3.9600.23291.

REFERENCES:

The following reports contain further technical details:
https://securityonline.info/certighost-cve-2026-54121/

[/emaillocker]
crossmenu