Glossary
AD CS ESC1
ESC1 is an Active Directory Certificate Services misconfiguration letting low-privileged users request certificates that impersonate any account.
ESC1 refers to a common misconfiguration in an Active Directory Certificate Services (AD CS) certificate template. It occurs when a template allows enrollees to supply an arbitrary Subject Alternative Name (SAN), permits client authentication, and grants enrollment rights to low-privileged users, all at once. Because the SAN field determines whose identity the issued certificate represents, a requester can simply specify a highly privileged account, such as a domain administrator, and receive a valid certificate usable to authenticate as that account.
This matters because certificate-based authentication is often overlooked compared to password and Kerberos ticket security, yet a single exploitable template can grant instant domain compromise to any authenticated user. Mitigation involves auditing certificate templates for this combination of flags, disabling the ability for requesters to specify SANs on templates that don't need it, and restricting enrollment permissions to only the accounts that genuinely require them.
See AD CS hardening.