Akamai, Microsoft Disagree on Severity of Unpatched ‘BadSuccessor’ Flaw

Akamai, Microsoft Disagree on Severity of Unpatched ‘BadSuccessor’ Flaw

Akamai has revealed a critical privilege-escalation vulnerability in Windows Server 2025’s Managed Service Accounts, which can allow attackers to compromise any user in Active Directory. Despite Microsoft dismissing it as moderate, Akamai’s disclosure highlights significant stealthy risks and the need for urgent attention before patches are available. #BadSuccessor #WindowsServer2025

Keypoints

  • Akamai disclosed details of a privilege-escalation flaw in Windows Server 2025 affecting Managed Service Accounts.
  • The vulnerability enables attackers to leverage Create-Child permissions to compromise any user in Active Directory.
  • Microsoft considers the flaw moderate, with no immediate patch planned, citing the need for future updates.
  • Akamai warns that default support for dMSAs in Windows Server 2025 increases exposure for organizations by inheriting existing permissions.
  • The disclosure includes detection guidance and tools to help organizations identify vulnerable accounts before patches are released.

Read More: https://www.securityweek.com/akamai-microsoft-disagree-on-severity-of-unpatched-badsuccessor-flaw/