Improper access control in Microsoft Windows and Windows Server - CVE-2025-33073
Published: June 10, 2025 / Updated: December 12, 2025
Vulnerability identifier: #VU110736
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-33073
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability:
The vulnerability is being exploited in the wild
Vulnerability details
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions in Windows SMB Client. A remote user can bypass implemented security restrictions and gain elevated privileges on the system.
Affected software
Microsoft Windows
Windows Server
Windows Server
How to mitigate CVE-2025-33073
Install updates from vendor's website.
Microsoft Windows - addressed in versions 10 21H2 10.0.19044.5965, 10 22H2 10.0.19045.5965, 10 1507 10.0.10240.21034, 10 1607 10.0.14393.8148, 10 1809 10.0.17763.7434, 11 22H2 10.0.22621.5472, 11 23H2 10.0.22631.5472, 11 24H2 10.0.26100.4270, 11 24H2 10.0.26100.4349
Windows Server - addressed in versions 2008 R2 6.1.7601.27769, 2008 6.0.6003.23351, 2012 R2 6.3.9600.22620, 2012 6.2.9200.25522, 2016 10.0.14393.8148, 2019 10.0.17763.7434, 2022 23H2 10.0.25398.1665, 2022 10.0.20348.3745, 2022 10.0.20348.3807, 2025 10.0.26100.4270, 2025 10.0.26100.4349
Windows Server - addressed in versions 2008 R2 6.1.7601.27769, 2008 6.0.6003.23351, 2012 R2 6.3.9600.22620, 2012 6.2.9200.25522, 2016 10.0.14393.8148, 2019 10.0.17763.7434, 2022 23H2 10.0.25398.1665, 2022 10.0.20348.3745, 2022 10.0.20348.3807, 2025 10.0.26100.4270, 2025 10.0.26100.4349
Links to Public Exploits and PoC-codes
- Exploit #12198 - CVE-2025-33073 (? Exploit CVE-2025-33073 with this universal tool for Windows Domain Controllers, enabling SYSTEM-level code execution through automated techniques.) (December 12, 2025)
- Exploit #12118 - CVE-2025-33073 (November 14, 2025)
- Exploit #12045 - windows-smb-vulnerability-framework-cve-2025-33073 (October 24, 2025)
- Exploit #11763 - CVE-2025-33073 (July 3, 2025)
- Exploit #11664 - CVE-2025-33073 (# CVE-2025-33073PoC Exploit for the NTLM reflection SMB flaw. All credits go to the official research: [Synacktiv](https://www.synacktiv.com/publications/ntlm-reflection-is-dead-long-live-ntlm-reflection-an-in-depth-analysis-of-cve-2025) ? (June 20, 2025)
- Exploit #11641 - CVE-2025-33073 (June 13, 2025)