
Eighteen from @hackthebox_eu is an assume breach Windows Server 2025 box featuring MSSQL impersonation, Werkzeug hash cracking, password spraying, and Bad Successor (CVE-2025-53779) to abuse dMSA migration for domain admin. https://0xdf.gitlab.io/2026/04/11/htb-eighteen.html
Post summary
The article outlines how CVE-2025-53779 (Bad Successor) is leveraged to abuse dMSA migration for domain admin in a Hack The Box Windows Server 2025 box, providing exploit details via the linked blog post.


