#VU109907 Permissions, Privileges, and Access Controls in Windows Server

 

#VU109907 Permissions, Privileges, and Access Controls in Windows Server

Published: May 28, 2025


Vulnerability identifier: #VU109907
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: N/A
CWE-ID: CWE-264
Exploitation vector: Adjecent network
Exploit availability: No public exploit available
Vulnerable software:
Windows Server
Software vendor:
Microsoft

Description

The vulnerability allows a remote user to escalate privileges within Active Directory.

The vulnerability exists due to improperly imposed security restrictions in Managed Service Accounts (dMSAs). A domain user with CreateChild permission can gain administrative privileges within Active Directory.

The vulnerability was dubbed BadSuccessor.


Remediation

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

External links