Virtual Event: Threat Detection & Incident Response Summit - Watch Now
Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Email Security

Akamai, Microsoft Disagree on Severity of Unpatched ‘BadSuccessor’ Flaw

Akamai documents a privilege escalation flaw in Windows Server 2025 after Redmond declines to ship an immediate patch.

Microsoft Patch Tuesday

Akamai’s security team kicked off a new spat in the vulnerability disclosure world by publishing full exploitation details for “BadSuccessor,” an unpatched privilege-escalation flaw in Windows Server 2025 that allows attackers to compromise any user in Active Directory.

According to Akamai researcher Yuval Gordon, Microsoft’s security response center confirmed the validity of the bug but brushed it aside as a “moderate” severity issue that would be patched  “in the future.” 

“While we appreciate Microsoft’s response, we respectfully disagree with the severity assessment,” Gordon argued in a blog post that included proof-of-concept code that turns an obscure service-account migration feature into a significant security risk.

Gordon said the weak spot lives in delegated Managed Service Accounts, or dMSAs, a brand-new account class introduced with Server 2025. The dMSAs were meant to replace clunky legacy service accounts but Gordon found that they inherit whatever powers the original account enjoyed.

He provided technical documentation to show the steps an unprivileged user can take to create a fresh dMSA that’s treated as a legitimate heir.

“This is all the Domain Controller needs to treat us as the legitimate heir. Remember: No group membership changes, no Domain Admins group touch, and no suspicious LDAP writes to the actual privileged account are needed,” Gordon said.

“With just two attribute changes, a humble new object is crowned the successor — and the KDC never questions the bloodline; if the link is there, the privileges are granted. We didn’t change a single group membership, didn’t elevate any existing account, and didn’t trip any traditional privilege escalation alerts,” he explained.

Advertisement. Scroll to continue reading.

Akamai surveyed customer telemetry and found that in 91 percent of environments, at least one non-admin user already holds the problematic Create-Child rights in an organizational unit.

Gordon notes that those rights are enough to spin up a dMSA but Microsoft reduced the severity because attackers would need “specific permissions indicative of elevated access.” Because Windows Server 2025 domain controllers enable dMSA support by default, Gordon said organizations inherit the risk simply by adding a 2025 DC to an existing Active Directory forest. 

He said that that default stance is what finally pushed Akamai to publish after notifying the software giant on April 1 and learning that a patch won’t be immediately available. 

“[They] assessed it as a Moderate severity vulnerability, and stated that it does not currently meet the threshold for immediate servicing,” Gordon said.

He warned that the vulnerability introduces a previously unknown and high-impact abuse path that makes it possible for any user with CreateChild permissions on an OU to compromise any user in the domain “and gain similar power to the Replicating Directory Changes privilege used to perform DCSync attacks.”

“Furthermore, we’ve found no indication that current industry practices or tools flag CreateChild access — or, more specifically, CreateChild for dMSAs — as a critical concern. We believe this underlines both the stealth and severity of the issue,” Gordon added.

The decision to disclose before a patch reignited the old responsible-disclosure debate. On social media, some researchers criticized Akamai for publishing full details of the attack patch before a patch is available. On the flip side, old-school hackers say Microsoft has a history of misdiagnosing and declining to fix serious security problems.

In the absence of an official patch, Akamai has published detection queries, logging guidance, and a script to locate principals that can create dMSAs. 

Related: Microsoft’s Security Chickens Have Come Home to Roost

Related: Pressure on Software Vendors Shipping Faulty, Incomplete Patches

Related:  Microsoft Purges Dormant Azure Tenants, Rotates Keys to Prevent Repeat Nation-State Hack 

Related: After Major Cloud Hacks, Microsoft Unveils ‘Secure Future Initiative’

Written By

Ryan Naraine is Editor-at-Large at SecurityWeek and host of the popular Security Conversations podcast series. He is a security community engagement expert who has built programs at major global brands, including Intel Corp., Bishop Fox and GReAT. Ryan is a founding-director of the Security Tinkerers non-profit, an advisor to early-stage entrepreneurs, and a regular speaker at security conferences around the world.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Delve into big-picture strategies to reduce attack surfaces, improve patch management, conduct post-incident forensics, and tools and tricks needed in a modern organization.

Register

Organizations are investing heavily in third-party risk management, but breaches, delays, and blind spots continue to persist. Join this live webinar as we examine the gap between how organizations think their third-party risk programs are performing and what’s actually happening in practice.

Register

People on the Move

Joe Chen has become Chief Technology Officer at Trellix.

Usercentrics has named Pawan Hegde as COO and Elena Ignatova as CPTO.

SecureAuth has named Mark van Oppen as Chief Revenue Officer.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.