Description
This module can create, read, update, and delete AD CS certificate templates from a Active Directory Domain Controller.
The READ, UPDATE, and DELETE actions will write a copy of the certificate template to disk that can be restored using the CREATE or UPDATE actions. The CREATE and UPDATE actions require a certificate template data file to be specified to define the attributes. Template data files are provided to create a template that is vulnerable to ESC1, ESC2, ESC3 and ESC15.
This module is capable of exploiting ESC4.
Module options
To display the available options, load the module within the Metasploit console and run the commands 'show options' or 'show advanced':
msf > use auxiliary/admin/ldap/ad/cs_cert_templatemsf undefined(cs_cert_template) > show actions ...actions...msf undefined(cs_cert_template) > set ACTION < action-name >msf undefined(cs_cert_template) > show options ...show and set options...msf undefined(cs_cert_template) > runPrioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub