BadSuccessor: From OU Access to Domain Admin
With the dMSA trust model explained, let’s get into the part 2, on how attackers weaponize it. The vulnerability—dubbed BadSuccessor—abuses the migration logic behind dMSAs to create a forged link between any service account and a privileged user. No actual migration required. No permissions over the target needed. Just write access to an Organizational Unit and a little Active Directory knowledge. I’m going to break down how attackers create fake dMSAs, forge migration attributes, and abuse Kerberos PAC inheritance to escalate privileges—all while staying nearly invisible to traditional detection....