Critical Windows Server 2025 dMSA Vulnerability Enables Active Directory Compromise
It has been shown that Windows Server 2025 includes a privilege escalation vulnerability that allows attackers to compromise any Active Directory (AD) user.
According to a post published with The Hacker News, Yuval Gordon, a security researcher at Akamai, stated that the attack is easy to deploy, works with the default configuration, and takes advantage of the delegated Managed Service Account (dMSA) functionality that was introduced in Windows Server 2025.
Most AD-reliant organizations are probably impacted by this problem. We discovered users with the necessary permissions to carry out this attack who were not members of the domain admins group in 91% of the environments we looked at.
Using a new feature called Delegated Managed Service Accounts (dMSA) that enables migration fr...

