CISA: High-severity Windows SMB flaw now exploited in attacks
ID: 985be4f8-3fbf-5e6e-a104-83fb6ee8f7af
STIX ID: report--985be4f8-3fbf-5e6e-a104-83fb6ee8f7af
Feed Name: Bleeping Computer
CVE-2025-33073 is a high-severity Windows SMB privilege escalation vulnerability affecting Windows Server, Windows 10, and Windows 11 up to 24H2; Microsoft issued a patch in June 2025 after researchers reported an improper access control weakness that can grant SYSTEM privileges when a victim is coerced to connect to a malicious SMB server. CISA reports active exploitation and added the flaw to its Known Exploited Vulnerabilities Catalog, directing federal agencies to patch within three weeks and urging all organizations to apply updates promptly.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
