ly4k / Certipy

Tool for Active Directory Certificate Services enumeration and abuse
MIT License
2.44k stars 340 forks source link

Forge Function Fails To Overwrite SIDs Present in Template Certificate #224

Open s7331 opened 2 months ago

s7331 commented 2 months ago

As pictured below, it is not possible to set a SID during the golden certificate forging process when a SID is already present in the template certificate. This poses problems as a SID is required to be both present and correct when KB5014754 is installed and enforced on targets.

NewPatchedBreaksForgedDebug