B
今週中
Microsoft Active Directory 証明書サービス (AD CS) において、低権限アカウントがドメインコントローラー (DC)…
📌 一言でいうと
Microsoft Active Directory 証明書サービス (AD CS) において、低権限アカウントがドメインコントローラー (DC) を偽装できる権限昇格の脆弱性「Certighost (CVE-2026-54121)」が発見されました。攻撃者は、証明書発行局の備援クエリメカニズムを悪用して、DCの身分情報を持つ証明書を不正に取得し、最終的にドメイン全体の制御権を奪取する可能性があります。Microsoftは2026年7月14日に修正プログラムをリリースしています。
🔍該当判定
- Windows Serverで「Active Directory 証明書サービス (AD CS)」をインストールして運用している
- 社内でデジタル証明書を発行し、PCやユーザーの認証(ログイン)に利用している
- 一般ユーザー権限で「コンピューターアカウント」を作成できる設定になっている
上記いずれにも該当しない → 静観でOK
✅該当時の対応
1. Microsoftが提供する最新のセキュリティ更新プログラムを適用すること。 2. 更新が困難な場合は、一時的にAD CSの備援クエリ機能を無効化することを検討し、既存の証明書申請フローへの影響を確認すること。
📧 メール案を見る (管理者向け)
⚠️ これは AI が生成した参考例です。配信前に必ず内容をご確認のうえ、貴社の状況に合わせて編集してご利用ください。実際の被害状況や自社の利用環境を踏まえた判断は、貴社のセキュリティ責任者にご確認ください。
件名: 【共有】Microsoft AD CS (CVE-2026-54121) 対応について
お疲れさまです。Microsoft AD CSの脆弱性「Certighost」に関する情報共有です。
■ 概要
AD CSの備援クエリメカニズムの不備により、低権限ユーザーがドメインコントローラー (DC) を偽装する証明書を取得できる権限昇格の脆弱性です。これにより、Kerberosのkrbtgtアカウントを含む機密情報の窃取や、ドメイン全体の制御権奪取に至るリスクがあります。
■ 影響範囲
- Microsoft Active Directory Certificate Services (AD CS)
■ 対応手順
1. 2026年7月14日にリリースされたMicrosoftのセキュリティ更新プログラムを適用してください。
2. 即時の更新が困難な環境では、備援クエリ機能の無効化を検討してください(※既存の証明書申請への影響について事前検証を推奨します)。
■ 参考情報
- Microsoft Security Update (July 2026)
対応優先度: 高
対応期限: 速やかに適用を推奨
お疲れさまです。Microsoft AD CSの脆弱性「Certighost」に関する情報共有です。
■ 概要
AD CSの備援クエリメカニズムの不備により、低権限ユーザーがドメインコントローラー (DC) を偽装する証明書を取得できる権限昇格の脆弱性です。これにより、Kerberosのkrbtgtアカウントを含む機密情報の窃取や、ドメイン全体の制御権奪取に至るリスクがあります。
■ 影響範囲
- Microsoft Active Directory Certificate Services (AD CS)
■ 対応手順
1. 2026年7月14日にリリースされたMicrosoftのセキュリティ更新プログラムを適用してください。
2. 即時の更新が困難な環境では、備援クエリ機能の無効化を検討してください(※既存の証明書申請への影響について事前検証を推奨します)。
■ 参考情報
- Microsoft Security Update (July 2026)
対応優先度: 高
対応期限: 速やかに適用を推奨
Subject: [Security Advisory] Microsoft AD CS Vulnerability (CVE-2026-54121)
Dear IT Administration Team,
We are sharing information regarding a critical privilege escalation vulnerability in Microsoft Active Directory Certificate Services (AD CS) known as "Certighost."
■ Overview
Due to a flaw in the fallback query mechanism of AD CS, an attacker with a low-privileged domain account can trick the Certificate Authority into issuing a certificate that impersonates a Domain Controller (DC). This could lead to the theft of domain secrets (including the krbtgt account) and full domain compromise.
■ Scope
- Microsoft Active Directory Certificate Services (AD CS)
■ Mitigation Steps
1. Apply the Microsoft security updates released on July 14, 2026.
2. If immediate patching is not possible, consider disabling the fallback query feature (Note: Please verify if this affects existing certificate request workflows first).
■ Reference
- Microsoft Security Update (July 2026)
Priority: High
Deadline: Immediate action recommended
Dear IT Administration Team,
We are sharing information regarding a critical privilege escalation vulnerability in Microsoft Active Directory Certificate Services (AD CS) known as "Certighost."
■ Overview
Due to a flaw in the fallback query mechanism of AD CS, an attacker with a low-privileged domain account can trick the Certificate Authority into issuing a certificate that impersonates a Domain Controller (DC). This could lead to the theft of domain secrets (including the krbtgt account) and full domain compromise.
■ Scope
- Microsoft Active Directory Certificate Services (AD CS)
■ Mitigation Steps
1. Apply the Microsoft security updates released on July 14, 2026.
2. If immediate patching is not possible, consider disabling the fallback query feature (Note: Please verify if this affects existing certificate request workflows first).
■ Reference
- Microsoft Security Update (July 2026)
Priority: High
Deadline: Immediate action recommended