Microsoft fixes "BadSuccessor" Kerberos vulnerability (CVE-2025-53779)
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-49712 | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. NVD description · AI analysis pending | 8.8 | 20% |
| — | ||
| CVE-2025-53731 +1 in the same advisory: …53740 | Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. NVD description · AI analysis pending | 8.4 | <1% |
| — | ||
| CVE-2025-53766 | Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code over a network. Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code over a network. NVD description · AI analysis pending | 9.8 | 7% |
| — | ||
| CVE-2025-53770 | Unauthenticated Deserialization RCE in Microsoft SharePoint Server on-premises CVE-2025-53770 is a deserialization of untrusted data vulnerability (CWE-502) in Microsoft SharePoint Server on-premises that allows an unauthorized attacker to execute code over a network. It is triggered when the server deserializes attacker-controlled data, can be chained with CVE-2025-53771, and it bypasses the fixes issued for CVE-2025-49704, meaning the earlier patches are insufficient. Successful exploitation yields remote code execution on the SharePoint server, and ransomware operators are known to be using it. Any organization running SharePoint Server on-premises is affected, particularly internet-facing deployments and end-of-life versions such as SharePoint Server 2013 and earlier that can no longer be patched. The flaw is being actively exploited — it was added to CISA's KEV on 2025-07-20 with known ransomware use — and EPSS assigns it a 100% probability of exploitation within 30 days. Do: Apply Microsoft's updated SharePoint Server security updates that fix CVE-2025-53770 — these include more robust protection than the earlier CVE-2025-49704 updates — and ensure the companion CVE-2025-53771 is also addressed, following CISA and vendor mitigation instructions for supported versions. Disconnect public-facing SharePoint Server 2013 or earlier (EOL/EOS) instances, minimize internet exposure of supported servers, and hunt for signs of compromise given the known ransomware exploitation. | 9.8 | 100% | KEV ransomware PoC ×3 |
| mass≈25,000–100,000 internet-exposed on-premises SharePoint servers (public internet-wide scans); total on-prem installed base plausibly >1M users | |
| CVE-2025-53771 | Improper Authentication in Microsoft SharePoint Server Enables Network Spoofing CVE-2025-53771 is an improper authentication flaw (CWE-287) in Microsoft's on-premises SharePoint Server that allows an unauthenticated remote attacker to conduct spoofing over the network. Per the CVSS vector, exploitation requires no privileges and no user interaction, so an attacker who can reach the SharePoint server over the network can trigger it directly. Successful exploitation lets the attacker impersonate an authenticated user or component, producing limited but real impact on confidentiality and integrity (CVSS 6.5, medium). Any organization running on-premises SharePoint Server is affected, particularly those exposing it to the internet; no specific version numbers are provided in the source data, so defenders should consult Microsoft's advisory for their edition. No public PoC exists and it is not yet in CISA's KEV, but exploitation likelihood is near-certain (EPSS 99.7%, 100th percentile), and Microsoft has confirmed active China-linked nation-state exploitation of the closely related SharePoint ToolShell vulnerability chain, which has hit roughly 400 organizations including U.S. federal agencies. Do: Apply Microsoft's SharePoint Server security updates that ship this fix as soon as possible, prioritizing internet-facing servers, and treat this as urgent because it was patched alongside the actively exploited ToolShell chain. While patching, review authentication and web-server logs on SharePoint hosts for unexpected successful logons or anomalous requests that could indicate spoofing or compromise, and restrict network access to SharePoint (VPN, firewall rules, segmentation) if patching must be delayed. | 6.5 | 100% |
| largeTens of thousands of internet-facing SharePoint Server deployments, with a total on-prem installed base plausibly in the hundreds of thousands (estimate) | ||
| CVE-2025-53778 | Improper Authentication in Microsoft Windows NTLM Enables Privilege Escalation CVE-2025-53778 is an improper authentication vulnerability (CWE-287) in the NTLM authentication implementation in Microsoft Windows, addressed as part of Microsoft's August 2025 Patch Tuesday release. An attacker who already holds valid low-privileged credentials can trigger the flaw by authenticating over the network to a vulnerable Windows host, causing the authentication check to be bypassed or mishandled. Successful exploitation results in elevation of privilege on the targeted system, with high impact on confidentiality, integrity, and availability. Affected systems span essentially all mainstream Windows releases in the data: Windows 10 (1507 through 22H2), Windows 11 (22H2 through 24H2), and Windows Server 2008 through 2019. No public proof-of-concept or confirmed in-the-wild exploitation is known and it is not in CISA KEV, but a high EPSS (38.9% probability of exploitation within 30 days, 98th percentile) indicates an elevated likelihood of exploitation in the near term. Do: Apply Microsoft's August 2025 security updates for all affected Windows 10, Windows 11, and Windows Server versions as soon as possible, prioritizing domain controllers, file servers, and other network-facing systems given the elevated EPSS. Audit NTLM usage in the environment and restrict or disable NTLM where Kerberos authentication is available, since the flaw resides in NTLM. Because exploitation requires valid credentials, review accounts with network logon rights and monitor for anomalous authenticated activity. | 8.8 | 39% |
| masswell over 1 billion Windows 10/11 client and Windows Server installations are potentially in scope (near-total coverage of the Windows installed base) | ||
| CVE-2025-53779 | Relative path traversal in Windows Kerberos allows an authorized attacker to elevate privileges over a network. Relative path traversal in Windows Kerberos allows an authorized attacker to elevate privileges over a network. NVD description · AI analysis pending | 7.2 | 3% |
| — | ||
| CVE-2025-53786 | On April 18th 2025, Microsoft announced Exchange Server Security Changes for Hybrid Deployments and accompanying non-security Hot Fix. On April 18th 2025, Microsoft announced Exchange Server Security Changes for Hybrid Deployments and accompanying non-security Hot Fix. Microsoft made these changes in the general interest of improving the security of hybrid Exchange deployments. Following further investigation, Microsoft identified specific security implications tied to the guidance and configuration steps outlined in the April announcement. Microsoft is issuing CVE-2025-53786 to document a vulnerability that is addressed by taking the steps documented with the April 18th announcement. Microsoft strongly recommends reading the information, installing the April 2025 (or later) Hot Fix and implementing the changes in your Exchange Server and hybrid environment. NVD description · AI analysis pending | 8.0 | 7% |
| — |
Full article855 words · extracted from helpnetsecurity.com · click to collapse
For August 2025 Patch Tuesday, Microsoft has released security updates resolving 100+ security vulnerabilities in its various solutions, including a relative path traversal flaw in Windows Kerberos (CVE-2025-53779) that allows an authorized attacker to elevate privileges over a network as part of a BadSuccessor attack.

The vulnerability, discovered by Akamai researcher Yuval Gordon, exploits the delegated Managed Service Account (dMSA) feature that was introduced in Windows Server 2025 and can be used to compromise any user in Active Directory (AD).
“An attacker who successfully exploited this vulnerability could gain domain administrator privileges,” Microsoft confirmed.
While the vulnerability has been known for months, there is currently no indication that it has been exploited in the wild. Microsoft rates the likelihood of exploitation as “less likely” and, consequently, does not consider this security update critical to deploy urgently.
“To exploit BadSuccessor, an attacker must have at least one domain controller in a domain running Windows Server 2025 in order to achieve domain compromise,” Satnam Narang, senior staff research engineer at Tenable, told Help Net Security.
He also noted that the flaw’s immediate impact is limited, as only 0.7% of AD domains had met the prerequisite at the time of disclosure.
Vulnerabilities that you should resolve quickly
“In the wake of last month’s ‘ToolShell’ zero-days (CVE-2025-53770 and CVE-2025-53771), which ravaged organizations through unauthenticated RCE exploits, Microsoft [has patched] another important deserialization bug: CVE-2025-49712,” says Saeed Abbasi, senior manager of security research with Qualys’ Threat Research Unit.
“This RCE demands authentication but pairs dangerously with known auth bypasses. Attackers chaining this with prior flaws could achieve full server compromise, and data exfiltration. It’s not yet exploited in the wild, but history shows these evolve fast, and exposed SharePoint instances are prime footholds for lateral movement. Prioritize and patch all SharePoint updates, rotate keys, and eliminate internet exposure. Delaying invites regulatory scrutiny and breaches since SharePoint’s exploit streak isn’t over.”
Dustin Childs, head of threat awareness at Trend Micro’s Zero Day Initiative, flagged CVE-2025-53731 and CVE-2025-53740, two Microsoft Office RCE vulnerabilities, as important to address sooner rather than later.
“This is the seventh month in a row where at least one Office component allowed code execution through the Preview Pane. With so many different components impacted, I doubt these are all patch bypasses. Instead, it appears attackers are mining code that hasn’t been looked at much and finding some gems. Perhaps it’s time to consider disabling the Preview Pane for a bit while the security gnomes in Redmond sort this out,” he advised.
CVE-2025-53766, a heap-based buffer overflow in Windows GDI+ (a graphics API used in Windows for rendering 2D graphics, images, and text) allows an unauthorized attacker to execute code over a network.
“An attacker could trigger this vulnerability by convincing a victim to download and open a document that contains a specially crafted metafile. In the worst-case scenario, an attacker could trigger this vulnerability on web services by uploading documents containing a specially crafted metafile without user interaction,” Microsoft explained (though still considers the flaw less likely to be exploited).
Childs gave an example of such a worst-case scenario: an attacker uploading something through an ad network that is served up to users.
“Ad blockers are just to remove annoyances; they also protect for malicious ads. They’re rare, but they have occurred in the past. Since GDI+ touches so many different components (and users tend to click on anything), test and deploy this one quickly,” he recommended.
On the other hand, CVE-2025-53778, an authenticated Windows NTLM elevation of privilege vulnerability with a low attack complexity, is considered by Microsoft more likely to be exploited, and should be addressed sooner rather than later.
Finally, if you’re running a hybrid deployment of Microsoft Exchange, be sure to check that you’re not among the (still to many) organizations that haven’t taken action to resolve CVE-2025-53786, a severe elevation of privilege flaw that pushed CISA to issue an emergency directive and guidance on how to address it.
“A successful exploit of CVE-2025-53786 would be highly disruptive. It exploits a bridge for an attacker to pivot from a compromised on-premises server directly into an organization’s cloud environment, potentially gaining administrative control over Exchange Online and other connected Microsoft 365 services,” says Ben McCarthy, lead cyber security engineer at Immersive.
An attack taking advantage of it would be difficult to detect in standard audit logs, he pointed out, and made sure to note that plugging this security hole requires more than just installing a patch.
“Administrators must also follow Microsoft’s manual configuration steps to create a dedicated service principal for the hybrid connection. This breaks the overly permissive shared trust, ensuring the on-prem server has only the limited permissions it truly needs,” he explained.
UPDATE (August 29, 2025, 04:50 a.m. ET):
Akamai researchers say Microsoft’s patch for CVE-2025-53779 (BadSuccessor) is effective in mitigating a significant part of the risk associated with BadSuccessor, but that “the technique lives on and remains relevant in certain scenarios.”

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2025/08/13/microsoft-fixes-badsuccessor-kerberos-vulnerability-cve-2025-53779/