# Windows Kerberos PKINIT / NTAuth certificate logon bypass

Source: https://startwithidentity.com/cves/cve-2025-26647/
Last updated: 2026-08-29
License: content by Start with Identity. Cite the source URL.

---

## What broke

The Windows Kerberos KDC accepted certificate-based logon (PKINIT) without the NTAuth store checks operators believed were in force. A crafted or mis-issued certificate becomes a domain logon. Microsoft patched this in April 2025 and tightened NTAuth enforcement. Getting the enforcement mode right is part of the fix, not an optional hardening note.

## Why it matters

Certificate logon is how smart cards, [Windows Hello](https://startwithidentity.com/glossary/passwordless/) for Business, and a lot of [AD CS](https://startwithidentity.com/glossary/pki/) abuse become a TGT. Combined with [CVE-2024-49019](https://startwithidentity.com/cves/cve-2024-49019/) (ESC15 / EKUwu) and the still-exploited [Certifried](https://startwithidentity.com/cves/cve-2022-26923/) mapping gap, 2025 was the year certificate authentication stopped being the "safe" Kerberos path.

## What to do

- Deploy the April 2025 Kerberos updates on every DC.
- Audit the NTAuth store. Only your intended enterprise CAs belong there.
- Turn on strong certificate mapping (KB5014754) if it is not already in enforcement. [CVE-2022-26923](https://startwithidentity.com/cves/cve-2022-26923/) is still showing up in incident response.
- Review [AD CS](https://startwithidentity.com/glossary/pki/) templates for ESC1-ESC16, not only this CVE.

## After you patch

Active Directory compromise is not contained by patching, because the artifacts an attacker creates outlive the vulnerability.

- **Rotate the krbtgt account twice**, with the replication interval between rotations, if there is any indication of ticket forgery. One rotation is not enough.
- **Audit AD CS certificate templates** for enrolment and enrollee-supplied-subject permissions, which are the most common escalation path left behind. See [certificate lifecycle](https://startwithidentity.com/glossary/certificate-lifecycle/).
- **Review privileged group membership and delegation rights** (Domain Admins, DnsAdmins, constrained and resource-based constrained delegation) for changes during the window.
- **Hunt for tickets with anomalous lifetimes or encryption types**, and for authentications to services that identity never touches.
- **Treat any issued certificate as a durable credential**: revoking a user's password does not revoke a certificate that authenticates as them. See [privilege escalation](https://startwithidentity.com/glossary/privilege-escalation/) and [lateral movement](https://startwithidentity.com/glossary/lateral-movement/).

## Sources

- [NVD: CVE-2025-26647](https://nvd.nist.gov/vuln/detail/CVE-2025-26647)
- Microsoft April 2025 security updates, NTAuth enforcement guidance
