CVE-2025-33073
Windows SMB Client Elevation of Privilege Vulnerability
Description
Improper access control in Windows SMB allows an authorized attacker to elevate privileges over a network.
In plain language
AI Act nowCVE-2025-33073 is a Windows SMB issue where an attacker with network access can gain higher privileges; most small businesses should treat it as urgent and patch soon.
CVE-2025-33073 is a Windows SMB Client elevation of privilege issue (CWE-284) where an authorized attacker can exploit improper access control to elevate privileges over the network; it is listed in CISA KEV with a remediation due date of 2025-11-10.
What to do now
- Check whether any of your devices run Microsoft Windows SMB Client on the affected versions (Windows Server 2008/2012/2012 R2/2008 R2/2016/2019/2022/2025 and Windows 10/11).
- For each affected device, confirm the installed Windows update level matches or exceeds the fixed version for your edition (see step 3).
- Apply the vendor fixes: upgrade Windows 10/Server 2016/Server 2019 to at least 10.0.19044.5965 / 10.0.19045.5965 / 10.0.17763.7434 / 10.0.14393.8148 as applicable; upgrade Windows 11 to at least 10.0.22621.5472 / 10.0.22631.5472 / 10.0.26100.4270 as applicable; upgrade Windows Server 2022 to at least 10.0.20348.3745 / 10.0.25398.1665 as applicable.
- If a system can’t be patched right away, use the vendor mitigation/workaround guidance from Microsoft Update Guide for CVE-2025-33073 and restrict or isolate SMB network access until patching is completed.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:LPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
References
- No Manners Here: The Ruthless Rise of The Gentlemen Ransomwareen-us·Palo Alto Unit 42· Exploited The Gentlemen ransomware
- The Gentlemen Ransomware Claims 478 Victims, Can Spread Like a Wormen·The Hacker News· Exploited The Gentlemen ransomware
- Thus Spoke…The Gentlemenen-us·Check Point Research· Incident Rocket The Gentlemen
- Киберугрозы 2025-2026: какие уязвимости были и будут в трендеru·Positive Technologies (Хабр)· Roundup rce
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2025-33073 and every CVE in our database. Create a free account — no credit card required.
Create Free Account