Support
 
Phone Get Quote
 
Support
 
US: +1 888 720 9500
US: +1 888 791 1189
Intl: +1 925 924 9500
Aus: +1 800 631 268
UK: 0800 028 6590
CN: +86 400 660 8680

Direct Inward Dialing: +1 408 916 9892

Banner Thumbnail
Attack Overview

BadSuccessor: The silent domain takeover hiding in plain sight

Year of occurrence: 2025 (discovered/active)

The vulnerability BadSuccessor (dMSA abuse)

A critical privilege escalation flaw known as BadSuccessor was uncovered in Windows Server 2025. It abuses the delegated Managed Service Account (dMSA) feature, which is meant to simplify service account management, and silently grants domain admin privileges.

By tampering with the msDS-ManagedAccountPrecededByLink attribute, attackers can trick Active Directory into granting a dMSA the same privileges as a high-level account such as a domain admin, without altering any existing accounts.

Severity Critical

This attack allows complete domain compromise through legitimate AD behavior. Yuval Gordon's analysis showed that in 91% of tested environments, users outside the Domain Admins group already had permissions that made this attack possible.

How it impacted organizations

BadSuccessor lets attackers:

Privilege escalation

Escalate privileges from a low-level user to full domain admin.

Detection bypass

Bypass detection, since no existing accounts or groups are modified.

Persistence

Maintain persistence within AD, exploiting its built-in trust model.

An attacker could take over your entire domain quietly and completely while security teams remain unaware.

With ADAudit Plus in place, organizations can

 
Active Alerts
  • Detect every dMSA creation or modification in real time, even by non-admins.
  • Receive instant alerts whenever the msDS-ManagedAccountPrecededByLink attribute was changed.
  • Trace who made the change, from where, and when, helping stop escalation before it spreads.
  • Audit OU permissions to identify users with dangerous dMSA management rights.
All AD changes

Outcome

With ADAudit Plus in place, the BadSuccessor attack can be detected before privilege escalation occurred, preventing attackers from silently seizing domain-wide control.

More security stories

Security story: CVE-2025-59287 – When the patch server becomes the attack vector

CVE-2025-59287: When the patch server becomes the attack vector

Security story: Password spraying – How five months of silent credential attacks went undetected

Password spraying: How five months of silence went undetected

Security story: Andariel's RID hijacking – When Windows trusted the wrong account

Andariel's RID hijacking: When Windows trusted the wrong account

Security story: The 2017 S3 breach – How four misconfigured buckets exposed an entire client base

The 2017 S3 breach: When four buckets exposed an entire client base

Schedule a personalized demo with our experts or see ADAudit Plus in action directly from your browser

ADAudit Plus Trusted By