Certighost and the Privilege Hiding in Your Certificate Authority
17/08/2026-17:00 17/08/2026-17:10 מחשבים וטכנולוגיה BleepingComputer דיווח
CVE-2026-54121 lets a standard domain user turn your Enterprise CA into a Domain Controller. The patch is the easy part. The lesson is standing privilege, implicit trust, and treating PKI as the Tier 0 identity infrastructure it has always been. [...]
סיכום מאמרפרצות בביטחון: חולשה חדשה במערכות ההפעלה של Microsoft בעקבות חשיפת CVE-2026-54121, ניתן למזער יוזר רגיל להפוך את מערכת ההפעלה של Enterprise CA למערכת מרכזת. התיקון עצמו אינו קשה, אך הלקח האמיתי הוא בניית זכויות עמידות, אמון בלתי מובהק וטיפול ב-PKI כבסיס הזהות המרכזי שהוא.תוכן זה נוצר על ידי בינה מלאכותית.