Hackers could abuse legitimate Windows AD FS to steal data
Hackers could spoof one AD FS server communicating to another AD FS to obtain its keys. The attack is not dissimilar to a Golden SAML attack that CyberArk coined in 2017. In that type of attack, hackers can access any application supporting SAML authentication with any privileges and be any user on the targeted application. In the new attack, hackers could abuse the Policy Store Transfer Service to acquire the encrypted Token Signing Certificate over the network. With previous techniques, hackers needed to execute remote code on an AD FS server to extract the data or at least an SMB connectio...