<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/unpatched-windows-server-2025-vulnerability-compromises-active-directory-gixkc49xw" -->

---
title: Unpatched Windows Server 2025 Vulnerability Compromises...
description: Akamai has discovered a vulnerability named &#x27;BadSuccessor&#x27; in Windows Server 2025&#x27;s Active Directory, affecting the Delegated Managed Service Accounts feature....
canonical: https://daily.dev/posts/unpatched-windows-server-2025-vulnerability-compromises-active-directory-gixkc49xw
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Unpatched Windows Server 2025 Vulnerability Compromises Active Directory | daily.dev
og:description: Akamai has discovered a vulnerability named &#x27;BadSuccessor&#x27; in Windows Server 2025&#x27;s Active Directory, affecting the Delegated Managed Service Accounts feature....
og:url: https://daily.dev/posts/unpatched-windows-server-2025-vulnerability-compromises-active-directory-gixkc49xw
og:image: https://api.daily.dev/og/posts/GiXKC49XW.png
og:image:alt: Unpatched Windows Server 2025 Vulnerability Compromises Active Directory
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Unpatched Windows Server 2025 Vulnerability Compromises Active Directory

**[Collections](https://daily.dev/sources/collections)** · 2 min read · 1 upvotes · 0 comments

## Summary

Akamai has discovered a vulnerability named 'BadSuccessor' in Windows Server 2025's Active Directory, affecting the Delegated Managed Service Accounts feature. This flaw enables privilege escalation, posing significant security risks for organizations using Active Directory. Microsoft is aware but has not yet released a patch. Security experts advise measures like restricting dMSA creation, monitoring account changes, and conducting regular audits to mitigate risks until a solution is provided.

## Content

# Understanding 'BadSuccessor': A Critical Vulnerability in Windows Server 2025 Active Directory

## Overview

In recent research, Akamai has identified a significant vulnerability known as 'BadSuccessor' within Microsoft Active Directory environments using Windows Server 2025. This vulnerability centers around the Delegated Managed Service Accounts (dMSA) feature and offers a pathway for attackers to escalate privileges and potentially take over domains.

## The Vulnerability

'BadSuccessor' allows users with specific permissions to impersonate other Active Directory users, including domain administrators, without changing account attributes or member groups. This opportunity for privilege escalation presents a formidable risk, particularly because it affects a vast number of organizations reliant on Active Directory for network management and security.

## Impact on Organizations

Given that Active Directory is widely used across numerous organizations, the presence of 'BadSuccessor' poses a critical threat to the integrity and security of their network operations. Microsoft has acknowledged the vulnerability but has yet to issue an immediate patch, resulting in the classification of this flaw as a moderate risk.

## Proactive Security Measures

In lieu of an immediate patch, security experts have recommended various proactive measures to mitigate risks associated with 'BadSuccessor':

- **Restrict the creation of Delegated Managed Service Accounts (dMSA):** Limiting who can create these accounts can reduce the attack surface.
- **Monitor account attribute changes:** Continuous observation of changes may help identify and prevent unauthorized access.
- **Audit permissions:** Regular audits can ensure that permissions remain secure and only trusted individuals have the necessary access rights.
- **Enhance security measures:** Employ detection tools provided by Akamai to identify potential vulnerabilities within systems.

## Future Directions

Akamai has reported 'BadSuccessor' to Microsoft, which plans to issue a patch addressing this vulnerability. In the meantime, organizations are encouraged to remain vigilant, ensuring their systems are adequately prepared against possible exploitation. By taking preventative security actions and staying informed about Microsoft updates, organizations can better safeguard their Active Directory environments from unauthorized access and potential compromise.

## Similar posts on daily.dev

- [Don’t just attend KubeCon \+ CloudNativeCon, Merge Forward your experience\!](https://daily.dev/posts/don-t-just-attend-kubecon-cloudnativecon-merge-forward-your-experience--l0rpp73x8) · CNCF · 1 upvotes · 0 comments
- [Announcing H2 2026 KCDs](https://daily.dev/posts/announcing-h2-2026-kcds-m96goajm1) · CNCF · 1 upvotes · 0 comments
- [Two months of Open Community Groups](https://daily.dev/posts/two-months-of-open-community-groups-asf52zhbs) · CNCF · 0 upvotes · 0 comments
- [CNCF Unveils Schedule for KubeCon \+ CloudNativeCon Europe 2026](https://daily.dev/posts/cncf-unveils-schedule-for-kubecon-cloudnativecon-europe-2026-ikhcoa5cb) · CNCF · 2 upvotes · 0 comments
- [CNCF Debuts KubeCon \+ CloudNativeCon Japan 2026 Schedule](https://daily.dev/posts/cncf-debuts-kubecon-cloudnativecon-japan-2026-schedule-xp5pyudub) · CNCF · 1 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#cyber](https://daily.dev/tags/cyber), [#microsoft](https://daily.dev/tags/microsoft), [#vulnerability](https://daily.dev/tags/vulnerability), [#active-directory](https://daily.dev/tags/active-directory)

[View this post on daily.dev](https://daily.dev/posts/unpatched-windows-server-2025-vulnerability-compromises-active-directory-gixkc49xw)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Unpatched Windows Server 2025 Vulnerability Compromises Active Directory","url":"https://daily.dev/posts/unpatched-windows-server-2025-vulnerability-compromises-active-directory-gixkc49xw","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/unpatched-windows-server-2025-vulnerability-compromises-active-directory-gixkc49xw"},"datePublished":"2025-05-22T13:19:43.063Z","dateModified":"2025-05-24T02:43:52.583Z","description":"Akamai has discovered a vulnerability named 'BadSuccessor' in Windows Server 2025's Active Directory, affecting the Delegated Managed Service Accounts feature....","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/7ee1f207b8b4f095b6f76e9a6665ade0?_a=AQAEuj9","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/7ee1f207b8b4f095b6f76e9a6665ade0?_a=AQAEuj9","isAccessibleForFree":true,"articleSection":"Collections","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Collections","logo":"https://media.daily.dev/image/upload/s--fk_6ycEi--/f_auto,q_auto/v1780996001/logos/collections?_a=BAMAMiWQ0","url":"https://daily.dev/sources/collections"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/unpatched-windows-server-2025-vulnerability-compromises-active-directory-gixkc49xw","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":1},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security,cyber,microsoft,vulnerability,active-directory","timeRequired":"PT2M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Collections","item":"https://daily.dev/sources/collections"},{"@type":"ListItem","position":3,"name":"Unpatched Windows Server 2025 Vulnerability Compromises Active Directory"}]}
```

