<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>CVE-2025-53779 on bokkapig</title><link>https://bokkapig.pages.dev/tags/cve-2025-53779/</link><description>Recent content in CVE-2025-53779 on bokkapig</description><generator>Hugo</generator><language>en-gb</language><lastBuildDate>Sat, 13 Jun 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://bokkapig.pages.dev/tags/cve-2025-53779/index.xml" rel="self" type="application/rss+xml"/><item><title>Checkpoint</title><link>https://bokkapig.pages.dev/writeups/checkpoint/</link><pubDate>Sat, 13 Jun 2026 00:00:00 +0000</pubDate><guid>https://bokkapig.pages.dev/writeups/checkpoint/</guid><description>Checkpoint is a Windows Server 2025 domain controller reachable only via AD services and SMB. Given creds alex.turner:Checkpoint2024! have no shell but hold Reanimate-Tombstones on the domain plus WriteProperty over a deleted user, mark.davies. Restoring the tombstone and abusing the post-patch BadSuccessor variant (CVE-2025-53779, dMSA credential theft — the KDC patch only blocks the one-way link, so you leak keys of any account you can write to) yields mark.davies&amp;rsquo; NT hash. mark.davies has WRITE on the DevDrop SMB share, whose contents are auto-installed as VS Code extensions by a scheduled task running as ryan.brooks — a malicious .vsix gives a shell and user.txt. ryan.brooks has CreateChild on OU=DMSAHolder and GenericWrite on svc_deploy, so a second BadSuccessor (split across alex to create the dMSA and ryan to set the superseded link) yields svc_deploy&amp;rsquo;s hash. svc_deploy is in BackupAccess and can read a VMware snapshot of an old Server 2019 DC in the VMBackups share; volatility3 + pypykatz against the 2GB .vmem recovers a local Administrator hash that is reused as the domain Administrator, giving DCSync and root.</description></item></channel></rss>