logo

CISA: High-severity Windows SMB flaw now exploited in attacks

ID: 985be4f8-3fbf-5e6e-a104-83fb6ee8f7af

STIX ID: report--985be4f8-3fbf-5e6e-a104-83fb6ee8f7af

Feed Name: Bleeping Computer

Threat Score
80/100

Date Published: 2025-10-20

Date Updated: 2026-07-18

Author: Sergiu Gatlan

...
...

CVE-2025-33073 is a high-severity Windows SMB privilege escalation vulnerability affecting Windows Server, Windows 10, and Windows 11 up to 24H2; Microsoft issued a patch in June 2025 after researchers reported an improper access control weakness that can grant SYSTEM privileges when a victim is coerced to connect to a malicious SMB server. CISA reports active exploitation and added the flaw to its Known Exploited Vulnerabilities Catalog, directing federal agencies to patch within three weeks and urging all organizations to apply updates promptly.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.