Vulnerability Management, Identity

Windows Server 2025 impacted by critical dMSA design issue

White silhouette of padlock made from different letters, numbers and special symbols. Concept of password-protected digital data and information security, computer technology

Windows Server 2025's delegated Managed Service Accounts have been impacted by a critical design vulnerability within its password-generation computation structure that could be leveraged for indefinite cross-domain lateral movement and persistence across managed service accounts and Active Directory resources through the new Golden dMSA attack technique, according to The Hacker News.

Malicious actors who have secured elevated privileges within a domain could launch the Golden dMSA attack to facilitate KDS root key material extraction via privilege escalation on domain controllers, dMSA account enumeration, ManagedPasswordID attribute and password hash discovery, and valid dMSA or gMSA password generation, a report from Semperis showed. Such a technique, which poses a significant persistence threat, indicates managed service accounts' "critical trust boundary," said Semperis researcher Adi Malyanker, who noted the possibility of the attack to allow a forest-wide persistent backdoor. "What starts as one DC compromise escalates to owning every dMSA-protected service across an entire enterprise forest. It's not just privilege escalation. It's enterprise-wide digital domination through a single cryptographic vulnerability," Malyanker added.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds