August 2025 brought a wave of high-severity vulnerabilities across Windows Server, Exchange, Android and Microsoft’s cloud services. The most important for most organizations is CVE-2025-53779, a Windows Kerberos flaw known as “BadSuccessor,” which can let an attacker who already has a foothold escalate to domain administrator and take over an entire Active Directory environment.
The flaw was publicly disclosed months before Microsoft shipped a fix in its August 12 Patch Tuesday release, which is why it was treated as a zero-day. Exploitation requires specific conditions, but the outcome, complete domain takeover, makes it a priority for any organization running Windows Server 2025 domain controllers. This briefing explains how BadSuccessor works, the other fixes from that month that deserved attention, and how to decide what to patch first.
What BadSuccessor is and why it matters
Windows Server 2025 introduced a new type of service account called a delegated Managed Service Account (dMSA). It was designed to make it easier to replace old service accounts: a dMSA can be linked to the account it supersedes and inherit its permissions during migration.
In May 2025, Akamai researcher Yuval Gordon showed that this migration feature could be abused. An attacker who can create or modify a dMSA, specifically by controlling two of its attributes (msds-groupMSAMembership and msds-ManagedAccountPrecededByLink), can mark any account, including a domain administrator, as its predecessor. Kerberos then grants the dMSA the privileges of that account. Microsoft rated the resulting elevation-of-privilege flaw 7.2 on the CVSS scale.
The critical detail is how commonly the precondition is met. The permission needed to create objects in an organizational unit is often delegated to help desk staff, service accounts or automation tools, and those accounts are rarely treated as sensitive. Akamai reported that in most of the environments it examined, users outside the Domain Admins group held permissions that would allow the attack. Only one Windows Server 2025 domain controller is needed for the technique to work.
Microsoft’s fix closes the path that allowed arbitrary accounts to be linked as predecessors. Because the technique was public and proof-of-concept tools circulated, attackers who gained any foothold in an unpatched domain had a known route to full control.
The rest of August 2025’s high-priority fixes
Microsoft’s August 2025 release addressed more than 100 vulnerabilities: 107 by Tenable’s count, or 111 including cloud and third-party issues, with more than a dozen rated Critical. Beyond BadSuccessor, several deserved fast attention:
- Exchange hybrid deployments (CVE-2025-53786). A flaw allowing an attacker with administrative access to an on-premises Exchange server to escalate into the connected Exchange Online tenant. CISA issued Emergency Directive 25-02 on August 7, 2025, requiring federal agencies to apply Microsoft’s configuration guidance.
- Graphics components. Critical remote code execution flaws in Windows graphics components, including GDI+ (CVE-2025-53766), which could be triggered by processing a crafted image or document.
- Message Queuing and NTLM. Critical flaws in Microsoft Message Queuing and an NTLM elevation-of-privilege issue that matter most on servers exposing those services.
- Microsoft 365 Copilot and Azure services. Several cloud-side vulnerabilities, including an information disclosure issue in Microsoft 365 Copilot’s Business Chat, were fixed by Microsoft directly and required no customer action, but they signal that AI assistants are now a meaningful attack surface.
- Android. Google’s August Android security bulletin included fixes for Qualcomm GPU flaws, among them CVE-2025-21479 and CVE-2025-27038, that had shown signs of limited, targeted exploitation.
Outside Microsoft, the same month saw active exploitation of a WinRAR path traversal flaw, CVE-2025-8088, which we covered in our WinRAR zero-day briefing.
How to prioritize patching
No organization can patch everything at once. A simple ranking keeps the most dangerous issues at the front of the queue:
- Actively exploited vulnerabilities first. Anything on CISA’s Known Exploited Vulnerabilities catalog or confirmed by the vendor as exploited should be patched within days.
- Publicly disclosed flaws with working exploit code. BadSuccessor falls here. Once a technique and tools are public, exploitation often follows quickly.
- Internet-facing and identity systems. Domain controllers, Exchange, VPNs, firewalls and remote access tools, where a single flaw can expose the whole organization.
- Critical remote code execution on widely deployed components. Such as the graphics and document-processing flaws that can be triggered by opening a file.
- Everything else on a regular cycle. Apply remaining updates within your standard monthly window after testing.
Where a patch cannot be applied immediately, for example because a domain controller upgrade needs a maintenance window, apply compensating controls: restrict the permissions an exploit depends on, increase monitoring on the affected systems, and set a firm date for the update. Record the exception so it is not quietly forgotten, which is how many breaches through long-known vulnerabilities begin.
Hardening Active Directory beyond the patch
Patching closes BadSuccessor, but the underlying lesson is about delegated permissions that nobody reviews. These steps reduce exposure to this class of attack:
- Audit who can create objects in each organizational unit. Remove the ability to create or modify dMSAs and other sensitive objects from accounts that do not need it.
- Monitor dMSA activity. Alert on creation of dMSAs and changes to the msds-ManagedAccountPrecededByLink attribute, which should be rare.
- Tier administrative access. Keep domain administrator accounts separate from everyday accounts and restrict where they can log in.
- Harden domain controllers. Limit interactive logons, remove unnecessary software, and treat any domain controller alert as high priority.
- Run an Active Directory security assessment. Tools that map attack paths reveal chains of permissions that lead from ordinary users to domain control.
Organizations facing tighter regulatory timelines should also read whether you are prepared for stricter patch deadlines.
Frequently asked questions
Does BadSuccessor affect us if we do not run Windows Server 2025?
The technique requires at least one Windows Server 2025 domain controller in the domain. Organizations without one were not exposed to this specific flaw, but should still review delegated permissions in Active Directory, since similar misconfigurations enable other attacks.
Was CVE-2025-53779 exploited in the wild?
At the time Microsoft released the fix, it was classified as publicly disclosed rather than actively exploited. Because the technique and proof-of-concept tools were public for months beforehand, it should be treated as high priority regardless.
How quickly should critical patches be applied?
Actively exploited and publicly disclosed critical vulnerabilities on internet-facing or identity systems should be patched within days. Other critical updates should follow within your regular cycle, ideally within two weeks.
Stay ahead of the next zero-day
Delana Technologies helps organizations prioritize and deploy security updates, harden Active Directory and monitor for exploitation of new vulnerabilities. Explore our cybersecurity and compliance services, call 239.414.5126 or contact us.
Sources: Microsoft Security Update Guide, August 2025 release; Akamai, “BadSuccessor: Abusing dMSA to Escalate Privileges in Active Directory” (May 2025); Tenable, “Microsoft’s August 2025 Patch Tuesday Addresses 107 CVEs”; The Hacker News, “Microsoft August 2025 Patch Tuesday Fixes Kerberos Zero-Day Among 111 Total New Flaws”; CISA Emergency Directive 25-02 (August 2025); Android Security Bulletin, August 2025.
