#badsuccessor — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #badsuccessor, aggregated by home.social.
-
Microsoft Patch Tuesday, August 2025 Edition https://krebsonsecurity.com/2025/08/microsoft-patch-tuesday-august-2025-edition/ #ExchangeServerSubscriptionEdition #MicrosoftExchangeServer #sansinternetstormcenter #ExchangeServer2016 #ExchangeServer2019 #MicrosoftOffice365 #LatestWarnings #TheComingStorm #CVE-2025-50165 #CVE-2025-53733 #CVE-2025-53766 #CVE-2025-53778 #CVE-2025-53779 #ExchangeOnline #MicrosoftWord #BadSuccessor #TimetoPatch #BenMcCarthy #WindowsGDI+ #YuvalGordon #Immersive #Akamai
-
Microsoft Patch Tuesday, August 2025 Edition
https://krebsonsecurity.com/2025/08/microsoft-patch-tuesday-august-2025-edition/
#ExchangeServerSubscriptionEdition #MicrosoftExchangeServer #sansinternetstormcenter #ExchangeServer2016 #ExchangeServer2019 #MicrosoftOffice365 #LatestWarnings #TheComingStorm #CVE-2025-50165 #CVE-2025-53733 #CVE-2025-53766 #CVE-2025-53778 #CVE-2025-53779 #ExchangeOnline #MicrosoftWord #BadSuccessor #TimetoPatch #BenMcCarthy #WindowsGDI+ #YuvalGordon #Immersive
-
Patch Tuesday, June 2025 Edition
https://krebsonsecurity.com/2025/06/patch-tuesday-june-2025-edition/
#WindowsServerMessageBlock #sansinternetstormcenter #PatchTuesdayJune2025 #ExperienceManager #CVE-2025-33053 #CVE-2025-33073 #mozillafirefox #SecurityTools #AcrobatReader #BadSuccessor #GoogleChrome #TimetoPatch #AdamBarnett #AlexVovk #SethHoyt #Action1 #Automox #Akamai #Rapid7 #WebDAV
-
Patch Tuesday, June 2025 Edition https://krebsonsecurity.com/2025/06/patch-tuesday-june-2025-edition/ #WindowsServerMessageBlock #sansinternetstormcenter #PatchTuesdayJune2025 #ExperienceManager #mozillafirefox #SecurityTools #AcrobatReader #BadSuccessor #CVE202533053 #CVE202533073 #GoogleChrome #TimetoPatch #AdamBarnett #AlexVovk #SethHoyt #Action1 #Automox #Akamai #Rapid7 #WebDAV
-
🤔 We have answers to your questions on #BadSuccessor, the latest AD vulnerability https://www.tenable.com/blog/frequently-asked-questions-about-badsuccessor
🕵️ Tenable Identity Exposure customers can check their exposure with our recently released Indicator of Exposure (IoE): https://www.tenable.com/indicators/ioe/ad/C-BAD-SUCCESSOR -
BadSuccessor Detection: Critical Windows Server Vulnerability Can Compromise Any User in Active Directory – Source: socprime.com https://ciso2ciso.com/badsuccessor-detection-critical-windows-server-vulnerability-can-compromise-any-user-in-active-directory-source-socprime-com/ #rssfeedpostgeneratorecho #CyberSecurityNews #ActiveDirectory #Latestthreats #Vulnerability #BadSuccessor #socprimecom #socprime #Blog
-
#WindowsServer2025: Rechteausweitungslücke im AD | Security https://www.heise.de/news/Windows-Server-2025-Rechteausweitungsluecke-im-AD-10397566.html #BadSuccessor #WindowsServer #Microsoft #Windows :windows: #MicrosoftWindows
-
Tiens, il y a un PoC d'exploitation pour la vulnérabilité BadSuccessor 👀
BadSuccessor, est une technique d'escalade de privilèges dans Active Directory. Elle exploite l’attribut peu connu dMSA ( delegated Managed Service Account) pour injecter un objet malveillant. Si un utilisateur a juste les droits "CreateChild" sur une OU (Organizational Unit), il peut créer un compte spécial et s’en servir pour devenir Domain Admin.
( 91% des environnements d'entreprise analysés par Akamai sont vulnérables à cette attaque. )
👇
https://www.akamai.com/blog/security-research/abusing-dmsa-for-privilege-escalation-in-active-directoryEt maintenant, il y a un PoC fonctionnel côté offensive.
⬇️
SharpSuccessor
Un outil .NET qui automatise le processus. Il permet à un utilisateur peu privilégié de :Créer un objet dMSA piégé dans une OU sur laquelle il a les droits "CreateChild"
Associer cet objet à sa propre session utilisateur
Et obtenir les privilèges de domaine admin
👇
https://github.com/logangoins/SharpSuccessor
Mitigation
"Until a formal patch is released by Microsoft, defensive efforts should focus on limiting the ability to create dMSAs and tightening permissions wherever possible."
Limiter les droits "CreateChild" :
Réviser les permissions sur les OU et restreindre la création d’objets aux seuls comptes administratifs de confiance.Surveiller les créations et modifications de dMSA :
Configurez des audits pour les événements AD pertinents (Event IDs 5136, 5137) afin de détecter toute activité suspecte liée aux dMSA.Utiliser des outils de détection :
Employer des scripts comme Get-BadSuccessorOUPermissions.ps1 ( https://github.com/akamai/BadSuccessor ) pour identifier les comptes ayant des permissions à risque pour remédiation.
[ dans les news infosec ]
⬇️
"SharpSuccessor PoC Released to Weaponize Windows Server 2025 BadSuccessor Flaw"
👇
https://gbhackers.com/sharpsuccessor-poc-released/ -
#Badsuccessor Nachlese - noch ein .NET Proof of Concept, um den Missbrauch der d;SA Privilege Escalation unter Windows Server 2025 DCs zu testen.
-
BadSuccessor Exploits Windows Server 2025 Flaw for Full AD Takeover https://hackread.com/badsuccessor-exploits-windows-server-2025-takeover/ #WindowsServer2025 #Cybersecurity #Vulnerability #BadSuccessor #Microsoft #Security #Akamai
-
BadSuccessor Exploits Windows Server 2025 Flaw for Full AD Takeover – Source:hackread.com https://ciso2ciso.com/badsuccessor-exploits-windows-server-2025-flaw-for-full-ad-takeover-sourcehackread-com/ #1CyberSecurityNewsPost #CyberSecurityNews #WindowsServer2025 #cybersecurity #Vulnerability #BadSuccessor #Microsoft #Hackread #security #Akamai
-
Akamai, Microsoft Disagree on Severity of Unpatched ‘BadSuccessor’ Flaw – Source: www.securityweek.com https://ciso2ciso.com/akamai-microsoft-disagree-on-severity-of-unpatched-badsuccessor-flaw-source-www-securityweek-com/ #rssfeedpostgeneratorecho #CyberSecurityNews #WindowsServer2025 #ActiveDirectory #Identity&Access #vulnerabilities #securityweekcom #emailsecurity #BadSuccessor #securityweek #Microsoft #Akamai
-
Akamai, Microsoft Disagree on Severity of Unpatched ‘BadSuccessor’ Flaw https://www.securityweek.com/akamai-microsoft-disagree-on-severity-of-unpatched-badsuccessor-flaw/ #WindowsServer2025 #Identity&Access #Vulnerabilities #ActiveDirectory #EmailSecurity #BadSuccessor #Microsoft #Akamai
-
Akamai, Microsoft Disagree on Severity of Unpatched ‘BadSuccessor’ Flaw https://www.securityweek.com/akamai-microsoft-disagree-on-severity-of-unpatched-badsuccessor-flaw/ #WindowsServer2025 #Identity&Access #Vulnerabilities #ActiveDirectory #EmailSecurity #BadSuccessor #Microsoft #Akamai
-
MT @The_Cyber_News
⚠️ New Attack Exploits dMSA in Windows Server 2025 to Compromise Any Active Directory Users
Read more: https://cybersecuritynews.com/attack-exploits-dmsa-windows-server-2025/
A critical vulnerability in Windows Server 2025 enables attackers to compromise any user in Active Directory, including highly privileged accounts.