Skip to content
KitploitKITPLOIT
ИнструментыЭксплойтыБлог
Log in
Отправить
ИнструментыЭксплойтыБлог
Отправить

Инструменты для хакинга, пентеста и кибербезопасности — ваш арсенал защиты!

Kitploit — это каталог инструментов для хакинга, кибербезопасности и пентестинга. Находите последние обновления проектов для поиска уязвимостей, анализа систем, автоматизации тестирования и усиления вашей безопасности.

··Ленты·Контакты·Конфиденциальность·© 2026 Kitploit

Каталог инструментов

Категории

Все категории
Loading categories
CVE-2026-54121-PoC-Exploit — 👻 CVE-2026-54121 - Best CertiGhost AD CS Multi-Exploit Framework | Advanced toolkit with rogue DC/LDAP servers, certificate abuse, PKINIT hash extraction. Features: detect safe check, exploit full multi-threaded. 🛡️ CVSS 8.8 High - Use Ethically, Stay Legal. 🔒 | Kitploit
Инструменты/GitHubGitHub/tc4dy/cve-2026-54121-poc-exploit
Authentication & AuthorizationPenetration Testing FrameworksPrivilege EscalationExploit FrameworksExploitationLateral MovementPost-ExploitationPayload Development

Популярное

Смотреть все →

Откройте для себя самые используемые инструменты нашего сообщества.

Изучить все инструменты

Просмотрите нашу коллекцию инструментов

Смотреть все инструменты →
Поделиться
GitHubtc4dy/cve-2026-54121-poc-exploit

CVE-2026-54121-PoC-Exploit

👻 CVE-2026-54121 - Best CertiGhost AD CS Multi-Exploit Framework | Advanced toolkit with rogue DC/LDAP servers, certificate abuse, PKINIT hash extraction. Features: detect safe check, exploit full multi-threaded. 🛡️ CVSS 8.8 High - Use Ethically, Stay Legal. 🔒

Репозиторий
276171 день назадПроверено Kitploit
Контент недоступен на запрошенном языке. Показываем английскую версию.

CVE-2026-54121

CVE-2026-54121 - AD CS "Certighost" Elevation of Privilege Framework-Toolkit

CVE-2026-54121 CVSS 8.8 Python 3.6+

Privilege Escalation Identity Impersonation Domain Admin

Active Directory Certificate Services — Certighost → Domain Takeover

Exploit Framework & Audit Toolkit
For authorized security testing only.


Legal Disclaimer & Responsible Use

This tool is provided for educational and authorized penetration testing purposes only. The authors and contributors are not responsible for any misuse or damage caused by this software. Users are solely responsible for ensuring they have explicit written permission from the target owner before testing. Unauthorized access to computer systems is illegal under applicable federal, state, and international cybercrime laws. By using this software, you agree to:

  • Use it only on systems you own or have explicit permission to test.
  • Comply with all applicable local, state, and federal laws.
  • Not use it for any malicious, destructive, or illegal activities.

[-!] Vulnerability Overview

CVE-2026-54121 (Dubbed "Certighost") is an Elevation of Privilege (EoP) vulnerability in Microsoft Active Directory Certificate Services (AD CS). It allows low-privileged domain users to impersonate Domain Controller machine accounts and achieve full Domain Admin takeover via certificate forgery.

How it works:

  1. Target Validation Bypass: The vulnerability exists due to improper authorization checks (CWE-285) in AD CS during the handling of certificate request target parameters.
  2. Rogue Server Redirection: The Certificate Authority (CA) accepts client-supplied server redirection targets without verifying whether the target is an authorized Domain Controller.
  3. Domain Controller Impersonation: The CA queries the attacker-controlled server and issues a valid computer certificate signed under the identity of a privileged Domain Controller.
  4. Domain Takeover (DCSync): Using the forged DC certificate, the attacker authenticates via Kerberos/PKINIT to gain Domain Controller privileges and execute DCSync operations.

Key Facts:

AttributeValue
[+] Discovered / PatchedJuly 2026 (Microsoft Patch Tuesday)
[+] CVSS Score8.8 (HIGH)
[+] CodenameCertighost
[+] Affected ProductsMicrosoft Active Directory Certificate Services
[+] Fixed VersionsJuly 2026 Security Update
[+] AuthenticationLow-Privileged Domain Account
[+] ImpactFull Active Directory Domain Compromise

Warning!

This code has been written with a user-friendly approach in mind and is fully functional, prioritizing security, privacy, and minimal logging. It is recommended that you completely remove the Shodan integration and library, use a single thread instead of a thread pool, remove port scanning and detect_ip, and disable logging and output. Use “stealthcert.py” for this version.


exploit.py vs stealthcert.py — Feature Comparison

Скачать инструмент