To access material, start machines and answer questions login.
Set up your virtual environment
This room explores -2022-26923 (opens in new tab), a vulnerability in Microsoft's Active Directory Certificate Service ( CS) that allows any user to escalate their privileges to Domain Admin in a single hop!
Research done and released as a whitepaper (opens in new tab) by SpecterOps showed that it was possible to exploit misconfigured certificate templates for privilege escalation and lateral movement. Based on the severity of the misconfiguration, it could allow any low-privileged user on the domain to escalate their privilege to that of an Enterprise Domain Admin with just a few clicks. If you are interested in learning more about these Certificate Template exploits, see this room.
Further research was performed by Oliver Lyak (opens in new tab), who discovered an additional vulnerability (-2022-26923) in the Certificate Service. A patch was released for the vulnerability by Microsoft on the 10th of May. You can read more about the research here (opens in new tab). This room provides a walkthrough of the exploitation of the vulnerability, as detailed in the research.
Start the to begin the room. You will be using to connect later in the room, so make sure to either use the or the AttackBox. The following low privileged credentials are provided below. Please allow around 5 minutes for the machine to fully boot.
Username: thm
Password: Password1@
Domain: lunar.eruca.com
Ready to learn Cyber Security?
The CVE-2022-26923 room is only available for Premium or Max subscribers. Signup now to access more than 500 free rooms and learn cyber security through a fun, interactive learning environment.
Already have an account? Log in

