Micropatches released for "Certighost" Active Directory Certificate Services Elevation of Privilege (CVE-2026-54121)

July 2026 Windows Updates brought a patch for CVE-2026-54121, an elevation of privilege vulnerability allowing an attacker to impersonate a computer account in a Windows domain, potentially resulting in complete domain compromise.
Security researchers Muhammad Ali and Aniq Fakhrul found this vulnerability and reported it to Microsoft. Muhammad and Aniq subsequently published a detailed article and shared a proof-of-concept tool that allowed us to reproduce the issue and create patches for legacy Windows users.
The Vulnerability
The vulnerability lies in Active Directory Certificate Services, specifically in the code that allows the requester of a certificate to specify that the CS should look up their identity in some other domain controller ("Client DC") than the default one in the domain. Insufficient validation of such request allowed the attacker to refer the CS to a malicious domain controller that provided fake information about the requestor. This could result in the attacker obtaining a valid certificate for an actual domain controller.
Microsoft's Patch
Microsoft fixed the issue by adding a security check to make sure the host referenced in the request's "Client DC" value is actually a valid domain controller in the domain.
Our Patch
Our patch is logically identical to Microsoft's.
Micropatch Availability
Micropatches were written for the following security-adopted Windows versions:
Windows Server 2008 R2 - fully updated with no ESU, with ESU 1, ESU 2, ESU 3 or ESU 4
Windows Server 2012 - fully updated with no ESU, with ESU 1 or ESU 2
Windows Server 2012 R2 - fully updated with no ESU, with ESU 1 or ESU 2
Micropatches have already been distributed to, and applied on, all affected online computers with 0patch Agent in PRO or Enterprise accounts (unless Enterprise group settings prevented that).
New vulnerabilities like these are discovered regularly, and attackers can eventually learn about and exploit them. If you're using Windows that aren't receiving official security updates anymore, 0patch will help prevent these vulnerabilities from being exploited on your computers - and you won't even have to know or care about these things.
We'd like to thank Muhammad Ali and Aniq Fakhrul for sharing their analysis and POC, which allowed us to create patches for Windows versions that are no longer receiving official updates from Microsoft.
If you're new to 0patch, create a free account in 0patch Central, start a free trial, then install and register 0patch Agent. Everything else will happen automatically. No computer reboot will be needed.
Did you know 0patch security-adopted Windows 10 and Office 2016 and 2019 when they went out of support in October 2025, allowing you to keep using them for at least 3 more years (5 years for Windows 10)? Read more about it here and here.
Note that we will soon security-adopt the following products:
Windows 10 22H2 with Extended Security Updates year 1: October 2026
Windows Server 2012 with Extended Security Updates year 3: October 2026
Windows Server 2012 R2 with Extended Security Updates year 3: October 2026
Microsoft Office 2021: October 2026
Windows 11 23H2 (E): November 2026
Windows Server 2016: January 2027
To learn more about 0patch, please visit our Help Center.