Reflecting on Your Tier Model: CVE-2025-33073 and the One-Hop Problem
ID: 38f7c0c2-fe1d-5892-b4d9-ea8a4e12d80f
STIX ID: report--38f7c0c2-fe1d-5892-b4d9-ea8a4e12d80f
Feed Name: Security Boulevard
Critical vulnerability CVE-2025-33073 enables abuse of unconstrained Kerberos delegation: any domain user with network access can obtain SYSTEM on unpatched member servers that lack SMB signing, making domain compromise trivial. The report urges immediate patching and prioritization of systems with unconstrained delegation, enabling SMB signing, marking privileged accounts as "sensitive and cannot be delegated" and adding them to Protected Users, running LSASS as a Protected Process Light, and monitoring for distinctive DNS record creation and self-authenticating SMB sessions for detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
