Misconfigured AD CS turns certificate issuance into a privilege-escalation path, not just PKI plumbing. Attackers can mint certificate-based identity that impersonates privileged accounts and slips past password-centric monitoring, so the real control point is certificate issuance and its logs.
Unit 42 says template misconfigurations and shadow credential abuse are being used together, including CVE-2022-26923 as an anchor for this class of AD CS abuse. The report ties the behavior to active use in the wild and adds behavioral detections for event log correlation and Cortex XDR alerts instead of a vendor patch.
The risk is durable impersonation of high-value identities across anything that trusts the CA. Even after passwords change, certificate-backed access can persist until the issued identity trail is found and removed.