專案

一般

配置概況

動作

專案資訊 #1075

進行中

專案資訊 #1064: 2025-PenTest

ADCS Web Enrollment Enabled for high-privileged accounts

是由 Joy Liao3 個月 前加入. 於 約 2 個月 前更新.

狀態:
Resolved-解决
優先權:
Normal
被分派者:
分類:
-
開始日期:
2025-08-01
完成日期:
2025-12-31 (逾期 25 天)
完成百分比:

100%

預估工時:

概述

N bookmark20250529113929916258883991 "ADCS Web Enrollment Enabled for high-privileged accounts

" Enabling ADCS Web Enrollment for high-privileged accounts increases the risk of credential theft, as attackers could exploit web-based vulnerabilities (like MITM or phishing) to intercept or forge certificates. This could lead to privilege escalation and domain compromise if abused for unauthorized authentication. "The following approaches are recommended to mitigate this potential vulnerability.

Enable Extended Protection for Authentication (EPA) on the ADCS Server.

Disable NTLM on the ADCS Server

Enforce SMB and LDAP Signing

"


檔案

動作

匯出至 Atom PDF