LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2025-33073: Microsoft Windows SMB Client Improper Access Control Vulnerability

RBRecent Breaches Vulnerability Intelligence·Oct 20, 2025
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Nov 10, 2025
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2025-33073 to its Known Exploited Vulnerabilities catalog on Oct 20, 2025, with a federal patch deadline of Nov 10, 2025 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Microsoft Windows SMB Client contains an improper access control vulnerability that could allow for privilege escalation. An attacker could execute a specially crafted malicious script to coerce the…

CVE-2025-33073 is an improper access control vulnerability in the Microsoft Windows SMB client. It can allow privilege escalation when an attacker coerces a victim machine to connect back over SMB and authenticate. For IT and security teams, this matters because Windows systems that use SMB are widespread, and successful abuse can elevate attacker control on the affected host. Confirm all version and patch details against the vendor advisory.

Public detail is limited to the CISA description of the issue; treat the vulnerability as a privilege-escalation risk in the SMB client path and prioritize inventory and remediation accordingly.

How it works

The weakness is classified as CWE-284 (Improper Access Control). In this class of flaw, the software fails to enforce correct restrictions on who or what can perform certain actions. According to the CISA summary, an attacker can execute a specially crafted malicious script that coerces the victim machine to connect back to an attacker-controlled system using SMB and authenticate. That coerced authentication and connection can then be leveraged for privilege escalation on the Windows host.

No further exploit mechanics, payloads, or prerequisites are provided in the available facts. Defenders should assume that any environment where the Windows SMB client can be induced to initiate outbound connections is in scope, and should verify exact attack conditions only against the Microsoft advisory.

Am I affected? How to find it in your systems

The vulnerability affects Microsoft Windows systems that include the SMB client. SMB client functionality is present on typical Windows workstations and servers that map network drives, access file shares, or otherwise initiate SMB connections.

For signs of exploitation, look for unexpected outbound SMB connections to unfamiliar hosts, anomalous authentication events tied to SMB client activity, and process or script execution that appears to force network connections. Correlate these with endpoint and network telemetry. Specific indicators of compromise are not supplied in the facts; treat unusual coerced-SMB patterns as suspicious and investigate.

How to remediate

Patch first. Apply the vendor update for this vulnerability as named in the Microsoft advisory for CVE-2025-33073. Follow the CISA required action: apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

If you can't patch immediately

Until the vendor update can be applied, reduce exposure with compensating controls appropriate to an SMB client privilege-escalation issue.

These steps lower risk but do not replace the official patch. Revisit the Microsoft advisory for any additional temporary mitigations.

If your data may have been exposed

Actively exploited vulnerabilities can lead to breaches even when ransomware use is not documented for this CVE. If you suspect compromise through this or related SMB activity, follow your incident response process: isolate affected hosts, preserve logs, reset credentials that may have been exposed via coerced authentication, and hunt for lateral movement. You can also run a free exposure scan of your email addresses against known breach data to check whether related credentials or personal information have appeared in prior incidents, then force password resets and enable multi-factor authentication where needed.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMicrosoft · Windows
WeaknessCWE-284
Added to CISA KEVOct 20, 2025
Federal patch deadlineNov 10, 2025
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities