
BadSuccessor: The silent domain takeover hiding in plain sight
Year of occurrence: 2025 (discovered/active)The vulnerability BadSuccessor (dMSA abuse)
A critical privilege escalation flaw known as BadSuccessor was uncovered in Windows Server 2025. It abuses the delegated Managed Service Account (dMSA) feature, which is meant to simplify service account management, and silently grants domain admin privileges.
By tampering with the msDS-ManagedAccountPrecededByLink attribute, attackers can trick Active Directory into granting a dMSA the same privileges as a high-level account such as a domain admin, without altering any existing accounts.
Severity Critical
This attack allows complete domain compromise through legitimate AD behavior. Yuval Gordon's analysis showed that in 91% of tested environments, users outside the Domain Admins group already had permissions that made this attack possible.
How it impacted organizations
BadSuccessor lets attackers:
Privilege escalation
Escalate privileges from a low-level user to full domain admin.
Detection bypass
Bypass detection, since no existing accounts or groups are modified.
Persistence
Maintain persistence within AD, exploiting its built-in trust model.
An attacker could take over your entire domain quietly and completely while security teams remain unaware.
With ADAudit Plus in place, organizations can
- Detect every dMSA creation or modification in real time, even by non-admins.
- Receive instant alerts whenever the msDS-ManagedAccountPrecededByLink attribute was changed.
- Trace who made the change, from where, and when, helping stop escalation before it spreads.
- Audit OU permissions to identify users with dangerous dMSA management rights.
Outcome
With ADAudit Plus in place, the BadSuccessor attack can be detected before privilege escalation occurred, preventing attackers from silently seizing domain-wide control.
