Permissions, Privileges, and Access Controls in Windows Server - #VU109907
Published: May 28, 2025
Windows Server
Detailed vulnerability description
The vulnerability allows a remote user to escalate privileges within Active Directory.
The vulnerability exists due to improperly imposed security restrictions in Managed Service Accounts (dMSAs). A domain user with CreateChild permission can gain administrative privileges within Active Directory.
The vulnerability was dubbed BadSuccessor.