CISOOnline

Certighost haunts Microsoft Active Directory Certificate Services

“When the validation gate is active, the CA checks that the hostname supplied in cdc resolves to a legitimate Domain Controller computer object in the real directory before it continues the chase,” the researchers confirmed. “A validation failure takes the request down an error path rather than the chase continuation.”

Although Microsoft has patched the vulnerability, organizations that depend on AD CS were asked to continuously audit certificate enrollment behavior, review exposed certificate templates, and ensure domain controllers and certificate authorities receive security updates promptly.

The researchers also provided a hotfix for organizations that cannot yet apply the fix. “If the July update cannot be installed immediately, the vulnerable code path can be switched off completely with a policy flag,” they said, adding the policy that can disable the chase fallback as it is optional.



Source link