MICROSOFT has addressed a severe vulnerability in its Active Directory (AD) Certificate Services, tracked as CVE-2026-54121, which allowed low-privileged users to impersonate a domain controller, potentially compromising the entire AD environment. The flaw stemmed from a broken trust boundary in the certificate enrollment process, enabling attackers to manipulate requests and extract sensitive identity information.
A proof-of-concept exploit was developed, revealing that the flaw could be exploited within a standard enterprise lab setup. Microsoft released a patch on July's Patch Tuesday, reinforcing target authenticity and object authenticity to prevent future exploits. Temporary mitigation strategies were suggested for organizations unable to immediately apply the patch.