Breaking In With Paper: Abusing AD CS ESC1 - Template Hijacking
How attackers exploit AD CS ESC1. A misconfigured certificate template that lets any domain user forge authentication certificates for privileged accounts and escalate to Domain Admin without cracking a single password.