A AegiFlow
UNKNOWNKNOWN EXPLOITED

CVE-2025-33073

Microsoft Windows SMB Client Improper Access Control Vulnerability

Published
2025-10-20
Modified
2026-07-31
Sources
cisa-kev

Summary

Microsoft Windows SMB Client contains an improper access control vulnerability that could allow for privilege escalation. An attacker could execute a specially crafted malicious script to coerce the victim machine to connect back to the attack system using SMB and authenticate.

References

Includes data from the CISA Known Exploited Vulnerabilities catalog.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.