CVE-2025-33073CISA KEV
Microsoft Windows SMB Client Improper Access Control Vulnerability
CISA lists this Microsoft vulnerability as known exploited. Its MSRC release detail is outside this installation's collected history.
CISA catalog record
Microsoft Windows SMB Client contains an improper access control vulnerability that could allow for privilege escalation. An attacker could execute a specially crafted malicious script to coerce the victim machine to connect back to the attack system using SMB and authenticate.
- Product
- Windows
- Added to KEV
- 20 Oct 2025
- Federal remediation due
- 10 Nov 2025
- Known ransomware use
- Not reported