Windows Server 2025 Golden dMSA Attack Enables Authentication Bypass and Password Generation

A critical design flaw in Microsoft’s latestWindows Server 2025enables attackers to bypass authentication and generate passwords for all managed service accounts across enterprise networks. The vulnerability, dubbed “Golden dMSA,” exploits a fundamental weakness in the newly introduced delegated Managed Service Accounts (dMSAs) that reduces complex cryptographic protections to a trivialbrute-force attackrequiring only 1,024 attempts. Semperis Security Researcher Adi Malyanker discovered the vuln...

Save to Folder

Choose a folder to save this article: