CVE-2025-33073
9.5 CISA KEVMicrosoft · Windows
An improper access control vulnerability in the Windows SMB client allows an authenticated remote attacker to elevate privileges to SYSTEM.
Executive summary
This critical privilege escalation vulnerability in Microsoft Windows is currently being exploited in the wild and requires immediate patching to prevent full system compromise.
Vulnerability
This is an NTLM reflection vulnerability involving improper access control in the SMB client. An authenticated attacker can bypass existing NTLM relay mitigations to execute arbitrary commands with SYSTEM-level privileges on systems that do not enforce SMB signing.
Business impact
With a CVSS score of 9.5, this vulnerability represents a critical risk to organizational infrastructure. Successful exploitation allows an attacker to gain full administrative control over compromised systems, leading to potential data exfiltration, lateral movement within the network, and complete service disruption. The inclusion of this vulnerability in the CISA Known Exploited Vulnerabilities catalog underscores the high probability of targeted attacks.
Remediation
Immediate Action: Apply the relevant security updates provided by Microsoft, specifically ensuring systems are updated to the versions listed in the vendor advisory or by applying the corresponding KBs: KB5060842, KB5060998, KB5060999, KB5061010, KB5060533, KB5060526, KB5060531, KB5060118, KB5061018, KB5061078, KB5061072, and KB5061059.
Proactive Monitoring: Audit network traffic for unusual SMB activity or NTLM authentication patterns that deviate from established baselines.
Compensating Controls: Enforce SMB signing across the environment to mitigate the risk of NTLM relay attacks where immediate patching is not feasible.
Exploitation status
Public Exploit Available: Yes, a weaponized exploit exists, and public proof-of-concept repositories are available via ExploitDB and GitHub.
Analyst recommendation
Due to confirmed active exploitation and the critical severity of this privilege escalation flaw, organizations must prioritize the deployment of the provided security patches across all affected Windows endpoints. Failure to remediate this vulnerability leaves systems highly susceptible to full administrative takeover by remote attackers. Immediate action is required to ensure the security and integrity of the affected environment.
More Microsoft CVEs
Sources
- Windows SMB Client Elevation of Privilege Vulnerability Vendor advisory