Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Einreichen
ToolsExploitsBlog
Einreichen

Hacking-, PenTest- und Cybersicherheits-Tools für Ihr Sicherheitsarsenal!

Kitploit ist ein Verzeichnis von Hacking-, Cybersicherheits- und Pentesting-Tools. Entdecken Sie die neuesten Projekt-Updates, um Schwachstellen zu finden, Systeme zu analysieren, Tests zu automatisieren und Ihre Sicherheit zu stärken.

··Feeds·Kontakt·Datenschutz·© 2026 Kitploit

Tool-Verzeichnis

Kategorien

Alle Kategorien anzeigen
Loading categories
CVE-2026-54121-PoC-Exploit — 👻 CVE-2026-54121 - Best CertiGhost AD CS Multi-Exploit Framework | Advanced toolkit with rogue DC/LDAP servers, certificate abuse, PKINIT hash extraction. Features: detect safe check, exploit full multi-threaded. 🛡️ CVSS 8.8 High - Use Ethically, Stay Legal. 🔒 | Kitploit
Tools/GitHubGitHub/tc4dy/cve-2026-54121-poc-exploit
Authentication & AuthorizationPenetration Testing FrameworksPrivilege EscalationExploit FrameworksExploitationLateral MovementPost-ExploitationPayload Development

Beliebteste

Alle anzeigen →

Entdecken Sie die meistgenutzten Tools unserer Community.

Alle Tools erkunden

Durchsuchen Sie unsere Tool-Sammlung

Alle Tools anzeigen →
Teilen
GitHubtc4dy/cve-2026-54121-poc-exploit

CVE-2026-54121-PoC-Exploit

👻 CVE-2026-54121 - Best CertiGhost AD CS Multi-Exploit Framework | Advanced toolkit with rogue DC/LDAP servers, certificate abuse, PKINIT hash extraction. Features: detect safe check, exploit full multi-threaded. 🛡️ CVSS 8.8 High - Use Ethically, Stay Legal. 🔒

Repository anzeigen
27617vor 1 TagVon Kitploit geprüft
Inhalt in der angeforderten Sprache nicht verfügbar. Englische Version wird angezeigt.

CVE-2026-54121

CVE-2026-54121 - AD CS "Certighost" Elevation of Privilege Framework-Toolkit

CVE-2026-54121 CVSS 8.8 Python 3.6+

Privilege Escalation Identity Impersonation Domain Admin

Active Directory Certificate Services — Certighost → Domain Takeover

Exploit Framework & Audit Toolkit
For authorized security testing only.


Legal Disclaimer & Responsible Use

This tool is provided for educational and authorized penetration testing purposes only. The authors and contributors are not responsible for any misuse or damage caused by this software. Users are solely responsible for ensuring they have explicit written permission from the target owner before testing. Unauthorized access to computer systems is illegal under applicable federal, state, and international cybercrime laws. By using this software, you agree to:

  • Use it only on systems you own or have explicit permission to test.
  • Comply with all applicable local, state, and federal laws.
  • Not use it for any malicious, destructive, or illegal activities.

[-!] Vulnerability Overview

CVE-2026-54121 (Dubbed "Certighost") is an Elevation of Privilege (EoP) vulnerability in Microsoft Active Directory Certificate Services (AD CS). It allows low-privileged domain users to impersonate Domain Controller machine accounts and achieve full Domain Admin takeover via certificate forgery.

How it works:

  1. Target Validation Bypass: The vulnerability exists due to improper authorization checks (CWE-285) in AD CS during the handling of certificate request target parameters.
  2. Rogue Server Redirection: The Certificate Authority (CA) accepts client-supplied server redirection targets without verifying whether the target is an authorized Domain Controller.
  3. Domain Controller Impersonation: The CA queries the attacker-controlled server and issues a valid computer certificate signed under the identity of a privileged Domain Controller.
  4. Domain Takeover (DCSync): Using the forged DC certificate, the attacker authenticates via Kerberos/PKINIT to gain Domain Controller privileges and execute DCSync operations.

Key Facts:

AttributeValue
[+] Discovered / PatchedJuly 2026 (Microsoft Patch Tuesday)
[+] CVSS Score8.8 (HIGH)
[+] CodenameCertighost
[+] Affected ProductsMicrosoft Active Directory Certificate Services
[+] Fixed VersionsJuly 2026 Security Update
[+] AuthenticationLow-Privileged Domain Account
[+] ImpactFull Active Directory Domain Compromise

Warning!

This code has been written with a user-friendly approach in mind and is fully functional, prioritizing security, privacy, and minimal logging. It is recommended that you completely remove the Shodan integration and library, use a single thread instead of a thread pool, remove port scanning and detect_ip, and disable logging and output. Use “stealthcert.py” for this version.


exploit.py vs stealthcert.py — Feature Comparison

Tool herunterladen