CVE-2025-53779
vulnerability analysis and mitigation

Overview

The Windows Kerberos vulnerability (CVE-2025-53779), also known as 'BadSuccessor', is a relative path traversal flaw discovered by Akamai researcher Yuval Gordon. The vulnerability was disclosed on May 21, 2025, and patched in Microsoft's August 2025 Patch Tuesday release. It affects Windows Server 2025 systems and allows an authorized attacker to elevate privileges over a network (Help Net Security, Tenable).

Technical details

The vulnerability has been assigned a CVSSv3 score of 7.2 (High) and is rated as moderate severity. It specifically exploits the delegated Managed Service Account (dMSA) feature introduced in Windows Server 2025. The vulnerability requires at least one domain controller in a domain running Windows Server 2025 to achieve domain compromise. At the time of disclosure, only 0.7% of AD domains met this prerequisite (Help Net Security).

Impact

A successful exploitation of this vulnerability could allow an attacker to gain domain administrator privileges and potentially achieve full domain and forest compromise in an Active Directory environment. The vulnerability affects organizations running Windows Server 2025 with specific Active Directory configurations (Help Net Security, Tenable).

Mitigation and workarounds

Microsoft has released security patches as part of the August 2025 Patch Tuesday update to address this vulnerability. Organizations running Windows Server 2025 should apply the security updates to protect against potential exploitation (Help Net Security).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management