CVE-2025-53779PoC(microsoft / windows_server_2025)

LOWCVSS 7.2 · HIGH

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

Relative path traversal in Windows Kerberos allows an authorized attacker to elevate privileges over a network.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-23

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • windows_server_2025

Threat summary

  • Public PoC is present in monitored signal
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 2 signals
  • Technical details provided in 2 signals
  • Exploit: 1 classified signal
  • Peaked at 2 mentions on most recent observed day (2026-04-13)
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
windows_server_2025

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-04-11: 1Mentions · 2026-04-13: 2PoC Mentioned / Linked · 2026-04-11: 1PoC Mentioned / Linked · 2026-04-13: 1Technical Details · 2026-04-11: 1Technical Details · 2026-04-13: 104-1104-13
Signal classification2 categories
PoC
266.7%
Exploit
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-111
Exploit1
2026-04-132
PoC2
Full discourse3 posts
  • 0xdf@0xdf_
    Exploit

    Eighteen from @hackthebox_eu is an assume breach Windows Server 2025 box featuring MSSQL impersonation, Werkzeug hash cracking, password spraying, and Bad Successor (CVE-2025-53779) to abuse dMSA migration for domain admin. https://0xdf.gitlab.io/2026/04/11/htb-eighteen.html

    Post summary

    The article outlines how CVE-2025-53779 (Bad Successor) is leveraged to abuse dMSA migration for domain admin in a Hack The Box Windows Server 2025 box, providing exploit details via the linked blog post.

    010057202.9K
    26.5K followersView on X
  • Darryl@_KScorpio
    PoC

    Published a write up for Eighteen from @hackthebox_eu. This could have been a medium machine because of the steps required to pwn it. It covers: - MSSQL Enumeration - RID brute force - BadSuccessor (CVE-2025-53779) https://scorpiosec.com/posts/htb-eighteen/

    Post summary

    A write-up for the Hack The Box machine "Eighteen" includes a PoC for CVE‑2025‑53779. The text provides no evidence of active exploitation, patches, or detailed technical info.

    020133409
    784 followersView on X
  • Xakep.ru@XakepRU
    PoC

    HTB Eighteen. Захватываем домен через уязвимость BadSuccessor Сегодня я покажу трюк повышения привилегий: имея минимальные права, можно через уязвимость BadSuccessor (CVE-2025-53779) связать свою dMSA с администратором и получить его ключи Kerberos. https://xakep.ru/2026/04/13/htb-eighteen/

    Post summary

    The post outlines how to exploit CVE-2025-53779 (BadSuccessor) to bind a compromised dMSA to an administrator and steal Kerberos keys, but it does not provide PoC code or evidence of active exploitation.

    00011537
    46.1K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
OSmicrosoftwindows_server_2025---

Explore more