CVE-2025-53778
8.8Microsoft · Windows
A vulnerability in Windows NTLM authentication allows an authorized network attacker to perform privilege escalation.
Executive summary
A critical privilege escalation vulnerability in Windows NTLM authentication allows an authenticated attacker to gain unauthorized system permissions over a network.
Vulnerability
This flaw stems from improper authentication handling within the NTLM protocol. An attacker who has already established a low privileged session can leverage this weakness to elevate their privileges to higher levels on the target system.
Business impact
The ability for an attacker to escalate privileges significantly increases the risk of a full system compromise, data theft, and unauthorized control over critical infrastructure. With a CVSS score of 8.8, this vulnerability is classified as High and represents a substantial threat to organizational security, as it allows attackers to bypass standard access controls and execute actions beyond their assigned roles.
Remediation
Immediate Action: Apply the relevant security updates provided by Microsoft in the official update guide to address the NTLM authentication flaw.
Proactive Monitoring: Monitor network and system authentication logs for unusual NTLM traffic patterns or multiple failed privilege escalation attempts across the network.
Compensating Controls: Implement network segmentation and restrict NTLM usage where possible, favoring more secure authentication protocols like Kerberos to limit the attack surface.
Exploitation status
Public Exploit Available: No (exploit_available unknown).
Analyst recommendation
Given the High severity of this privilege escalation flaw, organizations should prioritize patching affected Windows systems immediately. Failure to address this vulnerability exposes the environment to significant risk of unauthorized administrative access, and administrators should verify that all listed build versions are updated to the secure baseline specified by the vendor.
More Microsoft CVEs
Sources
- Windows NTLM Elevation of Privilege Vulnerability Vendor advisory