Synapse Consulting
Home SynapseRM / TPRM Services Pricing About BlogCareersLabsContact
EN · FR
Test access Book a demo
ACTIVE DIRECTORY

One certificate to rule them all: how ESC1 turns a user into a domain admin

Active Directory Certificate Services quietly issues the certificates that prove who is who across a Windows estate. When one template is misconfigured, an ordinary user can ask it for a certificate as the domain administrator, and it will say yes.

SYNAPSE CONSULTING  ·  14 AUGUST 2026  ·  2 MIN READ

Why the certificate authority is a crown jewel

An enterprise certificate authority is trusted by the whole domain. A certificate it issues is, in effect, a passport the domain will honour. That is why attackers love it: compromise the issuance rules and you do not need to steal a password, you mint an identity. Researchers at SpecterOps catalogued a family of these escalation paths, labelled ESC1 through the teens. ESC1 is the one you meet most often.

Low-priv userenrolment rights Request certificatevulnerable template,SAN = administrator CA issues certas any identity Domain AdminPKINIT auth as admin
ESC1: a low-privilege user requests a certificate from a vulnerable template, naming the administrator as the subject; the CA issues it; the attacker authenticates as that administrator.

ESC1 in plain terms

A certificate template is a form. It becomes dangerous when four conditions line up at once:

Put together, a normal user requests a certificate and simply types administrator as the subject. The CA issues it. The user then authenticates with that certificate through Kerberos PKINIT and is, to the entire domain, the administrator. Tools such as Certify and Certipy automate the whole path, which is why it does not take an expert.

How to see it and stop it

What it means for your register

ESC1 is not a software bug you patch; it is a configuration you have or you do not. That makes it a governance question, which is where a risk programme belongs. The certificate authority should be one of the highest-criticality assets in your inventory, with a named owner, a documented review of its templates, and that review dated and repeatable. An auditor who asks “when did you last review who can enrol from which template” is asking whether ESC1 is open. If the answer lives in one engineer’s memory, you cannot answer. If it lives in your register, you can.

Attack detail from Unit 42’s write-up on AD CS exploitation.

NEXT STEP
Bring us one real project

In a 45-minute session we run your own scope through SynapseRM: requirements, findings, scored risks, register entry. You keep the output either way.

Book a demo Request test access
Synapse Consulting

A Belgium-based provider of cybersecurity solutions, and the team behind SynapseRM / TPRM.

PLATFORM
SynapseRM / TPRM Pricing Test accessPresentation (PDF)
SERVICES
Governance Operational Training
COMPANY
About Contact Blog Careers Labs Privacy & cookies
Brussels, Belgium