Description
This module allows users to query a LDAP server for vulnerable certificate templates and will print these certificates out in a table along with which attack they are vulnerable to and the SIDs that can be used to enroll in that certificate template.
Additionally the module will also print out a list of known certificate servers along with info about which vulnerable certificate templates the certificate server allows enrollment in and which SIDs are authorized to use that certificate server to perform this enrollment operation.
Currently the module is capable of checking for certificates that are vulnerable to ESC1, ESC2, ESC3, ESC4, ESC13, and ESC15. The module is limited to checking for these techniques due to them being identifiable remotely from a normal user account by analyzing the objects in LDAP.
The module can also check for ESC9, ESC10 and ESC16 but this requires an Administrative WinRM session to be established to definitively check for these techniques.
Module options
To display the available options, load the module within the Metasploit console and run the commands 'show options' or 'show advanced':
msf > use auxiliary/gather/ldap/esc_vulnerable_cert_findermsf undefined(esc_vulnerable_cert_finder) > show actions ...actions...msf undefined(esc_vulnerable_cert_finder) > set ACTION < action-name >msf undefined(esc_vulnerable_cert_finder) > show options ...show and set options...msf undefined(esc_vulnerable_cert_finder) > runPrioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub