Skip to content

Add ESC1 exploitation variants (ESC1a/ESC1b/ESC1c) and EAB1/EAB2 - #378

Open
e1abrador wants to merge 1 commit into
ly4k:mainfrom
e1abrador:main
Open

e1abrador wants to merge 1 commit into
ly4k:mainfrom
e1abrador:main

Conversation

@e1abrador

Copy link
Copy Markdown

find:

  • ESC1: ESC1a (AMA CertPolicies injection), ESC1b (Security Extension SID passthrough) and ESC1c (Security Extension omission) are reported as per-template exploitation techniques in the ESC1 remark (they are strict subsets of ESC1), not as separate ESC findings
  • EAB1: V1 + ClientAuth (missing RA-Signature enforcement)
  • EAB2: V1/V2 EOBO target + CA without enrollment agent restrictions

req:

  • -certificate-policies: inject Certificate Policies (2.5.29.32) into the CSR (ESC1a)
  • -no-security-ext: omit szOID_NTDS_CA_SECURITY_EXT from the CSR (ESC1c)

find:
- ESC1: ESC1a (AMA CertPolicies injection), ESC1b (Security Extension SID
  passthrough) and ESC1c (Security Extension omission) are reported as
  per-template exploitation techniques in the ESC1 remark (they are strict
  subsets of ESC1), not as separate ESC findings
- EAB1: V1 + ClientAuth (missing RA-Signature enforcement)
- EAB2: V1/V2 EOBO target + CA without enrollment agent restrictions

req:
- -certificate-policies: inject Certificate Policies (2.5.29.32) into the CSR (ESC1a)
- -no-security-ext: omit szOID_NTDS_CA_SECURITY_EXT from the CSR (ESC1c)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant