#VU109907 Permissions, Privileges, and Access Controls in Windows Server
Published: May 28, 2025
Windows Server
Microsoft
Description
The vulnerability allows a remote user to escalate privileges within Active Directory.
The vulnerability exists due to improperly imposed security restrictions in Managed Service Accounts (dMSAs). A domain user with CreateChild permission can gain administrative privileges within Active Directory.
The vulnerability was dubbed BadSuccessor.