Semperis, a provider of AI-powered identity security and cyber resilience, released new research detailing Golden dMSA, a critical design flaw active in delegated Managed Service Accounts (dMSA) in Windows Server 2025.

The flaw can result in high-impact attacks, enabling cross-domain lateral movement and persistent access to all managed service accounts and their resources across Active Directory indefinitely.

Attack technique

To help further understanding of how this attack technique works in practice, Semperis researcher Adi Malyanker built a tool called GoldenDMSA.

The tool incorporates the logic of the attack, allowing users to efficiently explore, evaluate, and simulate how the technique may be exploited in real-world environments. The Golden dMSA attack leverages a cryptographic vulnerability that can undermine Microsoft's latest security innovation in Windows Server 2025. This technique exploits the architectural foundation of dMSAs.  

Critical design flaw

The ManagedPasswordId structure contains predictable time-based components with only 1,024 combinations

The attack leverages a critical design flaw: the ManagedPasswordId structure contains predictable time-based components with only 1,024 combinations, making brute-force password generation computationally trivial.

Golden dMSA exposes a critical design flaw that could let attackers generate service account passwords and persist undetected in Active Directory environments,” said Malyanker.

I built a tool that helps defenders and researchers better understand the mechanism of the attack. Organisations should proactively assess their systems to stay ahead of this emerging threat.”

New research

Semperis researchers, pioneers in identity threat detection, recently announced new research into nOauth, a known vulnerability in Microsoft’s Entra ID that enables full account takeover in vulnerable SaaS apps with minimal attacker effort.

In addition, new detection capabilities were developed in the company’s Directory Services Protector platform to enable defence against BadSuccessor, a high-severity privilege escalation technique targetting a newly introduced feature in Windows Server 2025.

Last year, Semperis researchers discovered Silver SAML, a new variant of the SolarWinds-era Golden SAML technique that bypasses standard defences in Entra ID-integrated applications.

In case you missed it

Responsible AI adoption starts with governance
Responsible AI adoption starts with governance

The eagerness to adopt AI in physical security is increasing as teams want to implement technology solutions for faster, smarter operations. At the same time, the conversations sur...

How AI-enabled cameras are becoming operational sensors that power safety, automation, and business intelligence
How AI-enabled cameras are becoming operational sensors that power safety, automation, and business intelligence

The biggest return on investment from an AI-enabled camera might have nothing to do with security. Organisations are increasingly discovering that the same cameras installed to pro...

Solink's AI agents boost efficiency of existing infrastructure with automation
Solink's AI agents boost efficiency of existing infrastructure with automation

Deploying artificial intelligence (AI) tools should be seen as a business initiative rather than a technology initiative, says Martin Soukup, CTO of Solink, a cloud-based video sec...