Windows SMB Client Vulnerability Exposes Organizations to Full Active Directory Compromise
ID: 16233832-9b6e-5c2a-8d7a-93bce89f5912
STIX ID: report--16233832-9b6e-5c2a-8d7a-93bce89f5912
Feed Name: GBHackers
CVE-2025-33073 is a critical logical flaw in the Windows SMB client NTLM reflection handling that allows authenticated attackers to relay authentication and inherit LSASS SYSTEM tokens, enabling SYSTEM-level privilege escalation and complete Active Directory compromise across domains; researchers demonstrate cross-protocol relay to LDAP/LDAPS (and Kerberos reflection variants), exploitation with modified public tools is trivial, many systems remain unpatched, and mitigations include applying Microsoft updates, enforcing SMB signing and channel binding, restricting DNS registration, and blocking NetNTLMv1.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
