AD CS ESC14 — altSecurityIdentities abuse

AD CS ESC14 — altSecurityIdentities abuse

TL;DR: Write access to a victim’s altSecurityIdentities attribute lets you forge certs that bind to the victim under strong cert mapping enforcement.

Stub — to be filled in.

What it is

TODO

Preconditions / where it applies

TODO

Technique

TODO

Detection and defence

TODO

References