Skip to content
KitploitKITPLOIT
工具博客
Log in
提交
工具博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
CVE-2026-54121-PoC-Exploit — 👻 CVE-2026-54121 - Best CertiGhost AD CS Multi-Exploit Framework | Advanced toolkit with rogue DC/LDAP servers, certificate abuse, PKINIT hash extraction. Features: detect safe check, exploit full multi-threaded. 🛡️ CVSS 8.8 High - Use Ethically, Stay Legal. 🔒 | Kitploit
工具/GitHubGitHub/tc4dy/cve-2026-54121-poc-exploit
Authentication & AuthorizationPenetration Testing FrameworksPrivilege EscalationExploit FrameworksExploitationLateral MovementPost-ExploitationPayload Development

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享
GitHubtc4dy/cve-2026-54121-poc-exploit

CVE-2026-54121-PoC-Exploit

👻 CVE-2026-54121 - Best CertiGhost AD CS Multi-Exploit Framework | Advanced toolkit with rogue DC/LDAP servers, certificate abuse, PKINIT hash extraction. Features: detect safe check, exploit full multi-threaded. 🛡️ CVSS 8.8 High - Use Ethically, Stay Legal. 🔒

查看仓库
276171天前Kitploit 审核通过
内容在请求的语言中不可用。显示英文版本。

CVE-2026-54121

CVE-2026-54121 - AD CS "Certighost" Elevation of Privilege Framework-Toolkit

CVE-2026-54121 CVSS 8.8 Python 3.6+

Privilege Escalation Identity Impersonation Domain Admin

Active Directory Certificate Services — Certighost → Domain Takeover

Exploit Framework & Audit Toolkit
For authorized security testing only.


Legal Disclaimer & Responsible Use

This tool is provided for educational and authorized penetration testing purposes only. The authors and contributors are not responsible for any misuse or damage caused by this software. Users are solely responsible for ensuring they have explicit written permission from the target owner before testing. Unauthorized access to computer systems is illegal under applicable federal, state, and international cybercrime laws. By using this software, you agree to:

  • Use it only on systems you own or have explicit permission to test.
  • Comply with all applicable local, state, and federal laws.
  • Not use it for any malicious, destructive, or illegal activities.

[-!] Vulnerability Overview

CVE-2026-54121 (Dubbed "Certighost") is an Elevation of Privilege (EoP) vulnerability in Microsoft Active Directory Certificate Services (AD CS). It allows low-privileged domain users to impersonate Domain Controller machine accounts and achieve full Domain Admin takeover via certificate forgery.

How it works:

  1. Target Validation Bypass: The vulnerability exists due to improper authorization checks (CWE-285) in AD CS during the handling of certificate request target parameters.
  2. Rogue Server Redirection: The Certificate Authority (CA) accepts client-supplied server redirection targets without verifying whether the target is an authorized Domain Controller.
  3. Domain Controller Impersonation: The CA queries the attacker-controlled server and issues a valid computer certificate signed under the identity of a privileged Domain Controller.
  4. Domain Takeover (DCSync): Using the forged DC certificate, the attacker authenticates via Kerberos/PKINIT to gain Domain Controller privileges and execute DCSync operations.

Key Facts:

AttributeValue
[+] Discovered / PatchedJuly 2026 (Microsoft Patch Tuesday)
[+] CVSS Score8.8 (HIGH)
[+] CodenameCertighost
[+] Affected ProductsMicrosoft Active Directory Certificate Services
[+] Fixed VersionsJuly 2026 Security Update
[+] AuthenticationLow-Privileged Domain Account
[+] ImpactFull Active Directory Domain Compromise

Warning!

This code has been written with a user-friendly approach in mind and is fully functional, prioritizing security, privacy, and minimal logging. It is recommended that you completely remove the Shodan integration and library, use a single thread instead of a thread pool, remove port scanning and detect_ip, and disable logging and output. Use “stealthcert.py” for this version.


exploit.py vs stealthcert.py — Feature Comparison

下载工具