diff --git a/Certify/Commands/Find.cs b/Certify/Commands/Find.cs index f3011c2..ccd74a0 100644 --- a/Certify/Commands/Find.cs +++ b/Certify/Commands/Find.cs @@ -736,7 +736,7 @@ private bool IsCertificateTemplateVulnerable(CertificateTemplate template, List< || !template.ExtendedKeyUsage.Any() // No EKUs == Any Purpose || template.ExtendedKeyUsage.Contains(CommonOids.AnyPurpose) || template.ExtendedKeyUsage.Contains(CommonOids.CertificateRequestAgent) - || template.ApplicationPolicies.Contains(CommonOids.CertificateRequestAgentPolicy); + || (template.ApplicationPolicies != null && template.ApplicationPolicies.Contains(CommonOids.CertificateRequestAgentPolicy)); if (lowPrivilegedUsersCanEnroll && hasDangerousEku) return true;