PT-2025-32855 · Google +4 · Android +6
Yug0Rd
+1
·
Published
2025-08-12
·
Updated
2025-08-31
·
CVE-2025-53779
9.0
High
Base vector | Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
**Name of the Vulnerable Software and Affected Versions:**
Windows Kerberos versions prior to August 2025 Patch Tuesday
**Description:**
A relative path traversal vulnerability in Windows Kerberos allows an authorized attacker to elevate privileges over a network. The vulnerability, also known as “BadSuccessor” (CVE-2025-53779), involves the abuse of delegated Managed Service Accounts (dMSAs) in Windows Server 2025, potentially allowing attackers to gain domain administrator rights. The vulnerability was actively exploited in the wild prior to the release of a patch. While the patch closes the direct privilege escalation path, the technique may still be applicable in certain scenarios and should be treated as a tactic, technique, and procedure (TTP) by defenders. Approximately 0.7% of Active Directory domains are affected.
**Recommendations:**
Install the August 2025 updates immediately.
Audit dMSA permissions.
Treat the BadSuccessor technique as a TTP even after applying the patch.
Fix
LPE
RCE
Relative Path Traversal
Weakness Enumeration
Related Identifiers
Affected Products
References · 65
- https://nvd.nist.gov/vuln/detail/CVE-2025-53779 · Security Note
- https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2025-53779 · Vendor Advisory
- https://bdu.fstec.ru/vul/2025-09690 · Security Note
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-53779 · Vendor Advisory
- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-53779 · Security Note
- https://twitter.com/akamai_research/status/1960752978077290618 · Twitter Post
- https://reddit.com/r/CVEWatch/comments/1n33c72/top_10_trending_cves_29082025 · Reddit Post
- https://twitter.com/The_Cyber_News/status/1961264396321349868 · Twitter Post
- https://reddit.com/r/ImpMSNews/comments/1mp059i/windows_11_kb5063878_kb5063875_august_2025_patch · Reddit Post
- https://twitter.com/Prismatecs/status/1959293309014167828 · Twitter Post
- https://twitter.com/TheCyberSecHub/status/1955627966542856469 · Twitter Post
- https://reddit.com/r/CVEWatch/comments/1n3xv8j/top_10_trending_cves_30082025 · Reddit Post
- https://twitter.com/Action1corp/status/1955324783505359219 · Twitter Post
- https://twitter.com/VaultEdgeIT/status/1955611579690467452 · Twitter Post
- https://twitter.com/Trej0Jass/status/1958762910932770869 · Twitter Post