Skip to content
KitploitKITPLOIT
FerramentasExploitsBlog
Log in
Enviar
FerramentasExploitsBlog
Enviar

Ferramentas de Hacking, PenTest e Cibersegurança para o seu Arsenal de Segurança!

Kitploit é um diretório de ferramentas de hacking, cibersegurança e pentesting. Descubra as últimas atualizações de projetos para encontrar vulnerabilidades, analisar sistemas, automatizar testes e fortalecer sua segurança.

··Feeds·Contato·Privacidade·© 2026 Kitploit

Diretório de Ferramentas

Categorias

Ver todas as categorias
Loading categories
CVE-2026-54121-PoC-Exploit — 👻 CVE-2026-54121 - Best CertiGhost AD CS Multi-Exploit Framework | Advanced toolkit with rogue DC/LDAP servers, certificate abuse, PKINIT hash extraction. Features: detect safe check, exploit full multi-threaded. 🛡️ CVSS 8.8 High - Use Ethically, Stay Legal. 🔒 | Kitploit
Ferramentas/GitHubGitHub/tc4dy/cve-2026-54121-poc-exploit
Authentication & AuthorizationPenetration Testing FrameworksPrivilege EscalationExploit FrameworksExploitationLateral MovementPost-ExploitationPayload Development

Mais Populares

Ver todos →

Descubra as ferramentas mais usadas pela nossa comunidade.

Explore todas as ferramentas

Navegue pela nossa coleção de ferramentas

Ver todas as ferramentas →
Compartilhar
GitHubtc4dy/cve-2026-54121-poc-exploit

CVE-2026-54121-PoC-Exploit

👻 CVE-2026-54121 - Best CertiGhost AD CS Multi-Exploit Framework | Advanced toolkit with rogue DC/LDAP servers, certificate abuse, PKINIT hash extraction. Features: detect safe check, exploit full multi-threaded. 🛡️ CVSS 8.8 High - Use Ethically, Stay Legal. 🔒

Ver Repositório
27617há 19h 40mRevisado pelo Kitploit
Conteúdo não disponível no idioma solicitado. Mostrando versão em inglês.

CVE-2026-54121

CVE-2026-54121 - AD CS "Certighost" Elevation of Privilege Framework-Toolkit

CVE-2026-54121 CVSS 8.8 Python 3.6+

Privilege Escalation Identity Impersonation Domain Admin

Active Directory Certificate Services — Certighost → Domain Takeover

Exploit Framework & Audit Toolkit
For authorized security testing only.


Legal Disclaimer & Responsible Use

This tool is provided for educational and authorized penetration testing purposes only. The authors and contributors are not responsible for any misuse or damage caused by this software. Users are solely responsible for ensuring they have explicit written permission from the target owner before testing. Unauthorized access to computer systems is illegal under applicable federal, state, and international cybercrime laws. By using this software, you agree to:

  • Use it only on systems you own or have explicit permission to test.
  • Comply with all applicable local, state, and federal laws.
  • Not use it for any malicious, destructive, or illegal activities.

[-!] Vulnerability Overview

CVE-2026-54121 (Dubbed "Certighost") is an Elevation of Privilege (EoP) vulnerability in Microsoft Active Directory Certificate Services (AD CS). It allows low-privileged domain users to impersonate Domain Controller machine accounts and achieve full Domain Admin takeover via certificate forgery.

How it works:

  1. Target Validation Bypass: The vulnerability exists due to improper authorization checks (CWE-285) in AD CS during the handling of certificate request target parameters.
  2. Rogue Server Redirection: The Certificate Authority (CA) accepts client-supplied server redirection targets without verifying whether the target is an authorized Domain Controller.
  3. Domain Controller Impersonation: The CA queries the attacker-controlled server and issues a valid computer certificate signed under the identity of a privileged Domain Controller.
  4. Domain Takeover (DCSync): Using the forged DC certificate, the attacker authenticates via Kerberos/PKINIT to gain Domain Controller privileges and execute DCSync operations.

Key Facts:

AttributeValue
[+] Discovered / PatchedJuly 2026 (Microsoft Patch Tuesday)
[+] CVSS Score8.8 (HIGH)
[+] CodenameCertighost
[+] Affected ProductsMicrosoft Active Directory Certificate Services
[+] Fixed VersionsJuly 2026 Security Update
[+] AuthenticationLow-Privileged Domain Account
[+] ImpactFull Active Directory Domain Compromise

Warning!

This code has been written with a user-friendly approach in mind and is fully functional, prioritizing security, privacy, and minimal logging. It is recommended that you completely remove the Shodan integration and library, use a single thread instead of a thread pool, remove port scanning and detect_ip, and disable logging and output. Use “stealthcert.py” for this version.


exploit.py vs stealthcert.py — Feature Comparison

Baixar ferramenta