You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
PingCastle does not report when computers are allowed to enroll for vulnerable certificate templates, so a direct critical path to DA remains undetected. e.g.:
Flag: EnrolleSuppliesSubject
EKU: Client / Server Authentication
Enrolement Rights: Domain Computers
PWN
The text was updated successfully, but these errors were encountered:
Hi there, Thanks for reporting this. This specific case is captured by PingCastle but only when the msds-MachineAccountQuota is not set to 0, which makes it even easier to exploit. I think Domain Computers on its own is a valid finding too so I have added this to the backlog for us to implement.
PingCastle does not report when computers are allowed to enroll for vulnerable certificate templates, so a direct critical path to DA remains undetected. e.g.:
The text was updated successfully, but these errors were encountered: