[ << ALL_FEED ]

Detecting CVE-2025-33073

More in General

Continuing previous publications, we explain how to detect the CVE-2025-33073 vulnerability 🕵️‍♂️

1️⃣ Monitor DNS queries with a Marshalled suffix

In Reflection Relay attacks, the attacker forces services to perform DNS queries to spoofed names with the pattern 1UWhRCA + 37–45 Base64 characters. Records like srv11UWhRCAAAAAAAAAAAAAAAAAAAAAAAAAAAAwbEAYBAAAA.example.com or localhost1UWhRCAAAAAAAAAAAAAAAAAAAAAAAAAAAAwbEAYBAAAA.example.com are indicators of a Reflection Relay attempt (NTLM, Kerberos).

• What to monitor

All DNS queries where the hostname ends with the marshalled part (1UWhRCA + 37-45 Base64 characters).

• Events

Sysmon Event ID 22 (DNS queries on hosts).

DNS server events containing such queries.

2️⃣ Catch LDAP searches with a marshalled suffix

Reflection Relay triggers LDAP queries from the attacked host to the domain controller, in which the name= parameter contains a spoofed DNS name in the format [hostname]1UWhRCA[Base64]. This occurs when performing a Relay attack back onto the victim.

• What to monitor:

LDAP queries in which the name= parameter contains the construct:
"[hostname]1UWhRCA[Base64 characters]"

• Events:

Windows Security Event 1644 ("A search was performed in Active Directory") on domain controllers.

3️⃣ Know the mechanics of CVE-2025-33073 and Coerce attacks

How the vulnerability works:

• Coerce attacks (PetitPotam, PrinterBug) force the victim to connect to a spoofed DNS name.
• Windows mistakenly considers the request local due to the marshalled suffix, disabling NTLM and Kerberos checks.
• This allows the attacker to relay the session back to the victim to gain RCE with SYSTEM privileges.

Examples of Coerce attacks:

• PetitPotam: coercion via a vulnerability in EFS RPC, forcing LSASS to initiate authentication;
• PrinterBug: forced sending of NTLM hashes via a vulnerability in the Windows print service (MS-RPRN).

4️⃣ Rely on examples of triggered correlation rules

When implementing CVE-2025-33073 together with PetitPotam to dump credentials, the following correlation rules triggered:

• Coerce_Auth: the rule detects Coerce attacks on a host aimed at intercepting the machine account hash of the attacked host, and also attempts to determine from the name of the pipe used which attack technique is being employed (netdfs = DFSCoerce; spoolss = PrinterBug; fssagentrpc = ShadowCoerce; efsrpc, lsarpc, samr, lsass, netlogon = PetitPotam; msftewds = WSPCoerce) and which tool is being used.

• SVCCTL_Connection: the rule detects a connection to the named pipe svcctl, which is responsible for remote configuration of Windows services on hosts via the Service Control Manager, which can lead to arbitrary code execution;

• Remote_Password_Dump: the rule detects a remote password dump via access to the named pipe WINREG.

5️⃣ Use examples of SIGMA rules

If you don’t have MaxPatrol SIEM, here are some examples of simple SIGMA rules:

For Sysmon Event ID 22.

For Windows Security Event 1644.

6️⃣ Use our public Suricata signatures to detect this attack

#detect #cve #win #sigma #rules
@ptescalator

More from global_author

More from global_author

More in General