ESC4
Vulnerable Certificate Template ACEs
Right | Description |
---|---|
| Implicit full control of the object, can edit any properties. |
| Full control of the object, can edit any properties. |
| Can modify the owner to an adversary-controlled principal. |
| Can modify access control to grant an adversary |
| Can edit any properties. |
Enumerate and Modify Templates
Automatically via Certipy:
A stealthier approach is to dump all properties of the vulnerable cert and modify only the needed parts in Certipy's code:
Last updated