Vulnerability record · CVE-2025-33073 · published 10 June 2025
CVE-2025-33073: Windows SMB improper access control allows privilege elevation
Microsoft · Windows 10 1507
Windows SMB contains an improper access control flaw (CWE-284) that lets an authorized attacker elevate privileges over the network. Microsoft rates it 8.8 HIGH, and CISA added it to the Known Exploited Vulnerabilities catalog, so it is being exploited in the wild. The description is thin on the exact mechanism, but the affected product list spans Windows 10, Windows 11 and Windows Server 2008 through 2025.
Description
Improper access control in Windows SMB allows an authorized attacker to elevate privileges over a network.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityIt is in CISA KEV with a near-top EPSS score and allows network-based privilege escalation to full system control across a very broad Windows install base.
What it is
Windows SMB contains an improper access control flaw (CWE-284) that lets an authorized attacker elevate privileges over the network. Microsoft rates it 8.8 HIGH, and CISA added it to the Known Exploited Vulnerabilities catalog, so it is being exploited in the wild. The description is thin on the exact mechanism, but the affected product list spans Windows 10, Windows 11 and Windows Server 2008 through 2025.
Impact
An attacker who already holds valid low-privileged credentials can gain high confidentiality, integrity and availability impact, effectively taking full control of the target system. This makes it a strong post-compromise escalation step inside a Windows environment.
Attack surface
Reachable over the network via SMB (AV:N, AC:L) with low privileges required (PR:L) and no user interaction (UI:N). The attacker needs some form of authorized access first, so this is not an unauthenticated remote entry point.
Exploitation
Listed in CISA KEV with a 2025-11-10 remediation due date, and EPSS is 0.827 (99.6th percentile), indicating active exploitation and high likelihood of follow-on attacks. No ransomware campaign association is recorded.
What to do
- Apply the Microsoft security update for CVE-2025-33073 to all affected Windows 10, Windows 11 and Windows Server versions; prioritize internet-facing and domain-critical hosts.
- Follow CISA BOD 22-01 guidance and meet the 2025-11-10 KEV due date, or discontinue use of unpatchable systems.
- Restrict SMB (TCP 445) exposure at network boundaries and between segments; block outbound SMB where it is not required.
- Enforce least privilege and limit where low-privileged accounts can authenticate, reducing the preconditions for the escalation.
- Monitor vendor and CISA advisories for updated mitigation guidance, since the public description does not detail the exact access control weakness.
Detection
- Hunt for anomalous SMB authentication and session activity, especially low-privileged accounts accessing SMB services they do not normally use.
- Alert on privilege changes or new high-integrity processes on hosts shortly after SMB connections from unusual sources.
- Correlate Windows security event logs for SMB logons (e.g. event IDs 4624 type 3) with subsequent token or privilege escalation indicators.
- Track unpatched Windows hosts in vulnerability scans against the affected product list and flag any still exposing SMB.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2025-33073 to the Known Exploited Vulnerabilities catalog on 20 October 2025 as "Microsoft Windows SMB Client Improper Access Control Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 10 November 2025.
Affected products
15 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-33073 | Vendor Advisory |
| https://www.vicarius.io/vsociety/posts/cve-2025-33073-detection-script-improper-access-control-in-windows-smb-affects-mi | Third Party Advisory |
| https://www.vicarius.io/vsociety/posts/cve-2025-33073-mitigation-script-improper-access-control-in-windows-smb-affects-m | MitigationThird Party Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-33073 | US Government Resource |
Track CVE-2025-33073 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2025-33073), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.