Skip to content

Glossary

AD CS ESC8

ESC8 is an AD CS weakness where NTLM authentication is relayed to certificate web enrollment endpoints to obtain a certificate for the victim.

ESC8 is one of the Active Directory Certificate Services escalation paths catalogued in the 2021 "Certified Pre-Owned" research. The HTTP-based enrollment interfaces — Certificate Authority Web Enrollment and the Certificate Enrollment Web Service — accept NTLM authentication and, in default configurations, do not require Extended Protection for Authentication. An attacker who can make a machine authenticate to them (for example through coercion such as PetitPotam) can relay that NTLM session and request a certificate in the victim's name, then use the certificate to authenticate via PKINIT.

It matters because relaying a domain controller's machine account this way yields a certificate for the DC, which is enough to perform DCSync and take over the domain. Remove Web Enrollment if it is not needed; otherwise require HTTPS, enable Extended Protection for Authentication, disable NTLM on the IIS site where possible, and enforce encryption on the RPC interface to address the related ESC11. Block coercion paths on DCs as a second layer.

See Securing AD CS web enrollment against NTLM relay and AD CS hardening.