
ESC17: From ADCS Misconfiguration to WSUS Client Compromise via DNS Zone Abuse
TLDR ESC17 is a new ADCS vulnerability class where a certificate template with Server Authentication EKU and Enrollee-Supplied Subject (SAN) allows a low-privileged user to obtain a valid TLS cert...








