Let’s Find if the environment running ADCS

 .\\Certify_Old.exe cas

Untitled

Notice that we found out that the environment is using CAs

First check is the Normal Users is allowed to enroll in the Template

Untitled

Now let’s Enumerate the Templates

.\\Certify_Old.exe find

Untitled

Notice that the dcorp RDP Users are allowed to enroll in this Template

ESC 1

The ESC 1 Abuse allow the normal users to ask for Certificates as Any Users including Domain Admins and Enterprise Admins users

Let’s Review the Vulnerability

Untitled

Let’s Enumerate the ESC 1 vulnerability

.\\Certify_Old.exe find /enrolleeSuppliesSubject 

Untitled