CVE Tools

CVE-2025-33073

Windows SMB Client Elevation of Privilege Vulnerability

Published: Jun 10, 2025Updated: Oct 27, 2025 Sources: CVE List NVD BDUCWE-284

Description

Improper access control in Windows SMB allows an authorized attacker to elevate privileges over a network.

In plain language

AI Act now

CVE-2025-33073 is a Windows SMB issue where an attacker with network access can gain higher privileges; most small businesses should treat it as urgent and patch soon.

Executive summary

CVE-2025-33073 is a Windows SMB Client elevation of privilege issue (CWE-284) where an authorized attacker can exploit improper access control to elevate privileges over the network; it is listed in CISA KEV with a remediation due date of 2025-11-10.

If affected, business impact
Complete takeover of affected systemsAccount and admin privilege escalationMalicious activity without clear accessDisruption from unauthorized control

What to do now

  1. Check whether any of your devices run Microsoft Windows SMB Client on the affected versions (Windows Server 2008/2012/2012 R2/2008 R2/2016/2019/2022/2025 and Windows 10/11).
  2. For each affected device, confirm the installed Windows update level matches or exceeds the fixed version for your edition (see step 3).
  3. Apply the vendor fixes: upgrade Windows 10/Server 2016/Server 2019 to at least 10.0.19044.5965 / 10.0.19045.5965 / 10.0.17763.7434 / 10.0.14393.8148 as applicable; upgrade Windows 11 to at least 10.0.22621.5472 / 10.0.22631.5472 / 10.0.26100.4270 as applicable; upgrade Windows Server 2022 to at least 10.0.20348.3745 / 10.0.25398.1665 as applicable.
  4. If a system can’t be patched right away, use the vendor mitigation/workaround guidance from Microsoft Update Guide for CVE-2025-33073 and restrict or isolate SMB network access until patching is completed.
Patch / advisory Usually a quick update

CVSS Vector Breakdown

AV:NAC:LPR:LUI:NS:UC:HI:HA:H
Exploitability
AV:NAttack Vector
Network
AC:LAttack Complexity
Low
PR:LPrivileges Required
Low
UI:NUser Interaction
None
Scope
S:UScope
Unchanged
Impact
C:HConfidentiality
High
I:HIntegrity
High
A:HAvailability
High

Weaknesses

Affected Products

and 57 more affected products View all →

Exploitability

CISA Known Exploited Vulnerability
Added to KEV:Oct 20, 2025
Remediation due:Nov 10, 2025

Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Official Patch Available
Workaround Available

References

and 6 more references View all →
4

Unlock Complete Vulnerability Intelligence

Get the full picture for CVE-2025-33073 and every CVE in our database. Create a free account — no credit card required.

Create Free Account
Plain-language analysis
Impact assessment and exploitation scenario in plain English
Attack graph visualization
Interactive attack path and kill chain mapping
Exploit details & PoC links
ExploitDB, Metasploit, GitHub PoCs with direct links
Nuclei scanner templates
Ready-to-use vulnerability scanner templates
Full remediation guide
Patch instructions, workarounds, and compliance impact
Interactive AI chat
Ask questions about this vulnerability in natural language
Related vulnerabilities
Semantically similar CVEs and attack patterns
REST API & MCP access
Integrate vulnerability data into your workflows