F-08 — Certificate template lets any domain user authenticate as a domain administrator (AD CS ESC1)
What we found. The certificate template User-Legacy on the enterprise CA lets the requester supply the subject alternative name, carries the Client Authentication EKU, needs no manager approval, and grants Enroll to Domain Users. Any domain account can request a certificate naming a domain administrator and log on with it as that administrator.
How to reproduce. From a standard domain account created for the test, request a certificate from User-Legacy with the SAN set to a domain administrator’s UPN, then authenticate to a domain controller with it over PKINIT. The request, the issued certificate and the resulting ticket are in the evidence pack, f08-adcs.log.
Consequence. Any phished or guessed staff password becomes control of the domain in one step, and with it every server, mailbox and backup joined to it.
Fix. Remove the enrollee-supplied subject flag from the template, or restrict Enroll to the group that needs it and require CA manager approval. Review the other published templates for the same combination (see F-09). Verify by repeating the same request: it should be refused.

ARTA CYBER