Rapid7 Vulnerability & Exploit Database

AD CS Certificate Template Management

Back to Search

AD CS Certificate Template Management



This module can create, read, update, and delete AD CS certificate templates from a Active Directory Domain Controller. The READ, UPDATE, and DELETE actions will write a copy of the certificate template to disk that can be restored using the CREATE or UPDATE actions. The CREATE and UPDATE actions require a certificate template data file to be specified to define the attributes. Template data files are provided to create a template that is vulnerable to ESC1, ESC2, and ESC3. This module is capable of exploiting ESC4.


  • Will Schroeder
  • Lee Christensen
  • Oliver Lyak
  • Spencer McIntyre


Module Options

To display the available options, load the module within the Metasploit console and run the commands 'show options' or 'show advanced':

msf > use auxiliary/admin/ldap/ad_cs_cert_template
msf auxiliary(ad_cs_cert_template) > show actions
msf auxiliary(ad_cs_cert_template) > set ACTION < action-name >
msf auxiliary(ad_cs_cert_template) > show options
    ...show and set options...
msf auxiliary(ad_cs_cert_template) > run 

Time is precious, so I don’t want to do something manually that I can automate. Leveraging the Metasploit Framework when automating any task keeps us from having to re-create the wheel as we can use the existing libraries and focus our efforts where it matters.

– Jim O’Gorman | President, Offensive Security