Detecting CVE-2025-33073

More in General
- We helped Apple fix a vulnerability in the kernel of its operating systems
We helped Apple fix a vulnerability in the kernel of its operating systems PT ESC expert…
- Recovering EVTX records: carving methods
Recovering EVTX records: carving methods 🧩 When investigating incidents where attackers encrypt virtual machine images, a…
- Operation Chewbacca
At the end of June, the PT ESC team, during incident investigations, discovered a new group…
- Your Zimbra server is at risk
Recently, our PT ESC IR team encountered a new attack by ransomware groups on Zimbra mail…
- He's not your gsocket
He's not gsocket to you 😑 During the investigation of one of the incidents, PT ESC…
Continuing previous publications, we explain how to detect the CVE-2025-33073 vulnerability 🕵️♂️
1️⃣ Monitor DNS queries with a Marshalled suffix
In Reflection Relay attacks, the attacker forces services to perform DNS queries to spoofed names with the pattern 1UWhRCA + 37–45 Base64 characters. Records like srv11UWhRCAAAAAAAAAAAAAAAAAAAAAAAAAAAAwbEAYBAAAA.example.com or localhost1UWhRCAAAAAAAAAAAAAAAAAAAAAAAAAAAAwbEAYBAAAA.example.com are indicators of a Reflection Relay attempt (NTLM, Kerberos).
• What to monitor
All DNS queries where the hostname ends with the marshalled part (1UWhRCA + 37-45 Base64 characters).
• Events
Sysmon Event ID 22 (DNS queries on hosts).
DNS server events containing such queries.
2️⃣ Catch LDAP searches with a marshalled suffix
Reflection Relay triggers LDAP queries from the attacked host to the domain controller, in which the name= parameter contains a spoofed DNS name in the format [hostname]1UWhRCA[Base64]. This occurs when performing a Relay attack back onto the victim.
• What to monitor:
LDAP queries in which the name= parameter contains the construct:
"[hostname]1UWhRCA[Base64 characters]"
• Events:
Windows Security Event 1644 ("A search was performed in Active Directory") on domain controllers.
3️⃣ Know the mechanics of CVE-2025-33073 and Coerce attacks
How the vulnerability works:
• Coerce attacks (PetitPotam, PrinterBug) force the victim to connect to a spoofed DNS name.
• Windows mistakenly considers the request local due to the marshalled suffix, disabling NTLM and Kerberos checks.
• This allows the attacker to relay the session back to the victim to gain RCE with SYSTEM privileges.
Examples of Coerce attacks:
• PetitPotam: coercion via a vulnerability in EFS RPC, forcing LSASS to initiate authentication;
• PrinterBug: forced sending of NTLM hashes via a vulnerability in the Windows print service (MS-RPRN).
4️⃣ Rely on examples of triggered correlation rules
When implementing CVE-2025-33073 together with PetitPotam to dump credentials, the following correlation rules triggered:
• Coerce_Auth: the rule detects Coerce attacks on a host aimed at intercepting the machine account hash of the attacked host, and also attempts to determine from the name of the pipe used which attack technique is being employed (netdfs = DFSCoerce; spoolss = PrinterBug; fssagentrpc = ShadowCoerce; efsrpc, lsarpc, samr, lsass, netlogon = PetitPotam; msftewds = WSPCoerce) and which tool is being used.
• SVCCTL_Connection: the rule detects a connection to the named pipe svcctl, which is responsible for remote configuration of Windows services on hosts via the Service Control Manager, which can lead to arbitrary code execution;
• Remote_Password_Dump: the rule detects a remote password dump via access to the named pipe WINREG.
5️⃣ Use examples of SIGMA rules
If you don’t have MaxPatrol SIEM, here are some examples of simple SIGMA rules:
For Windows Security Event 1644.
6️⃣ Use our public Suricata signatures to detect this attack


#detect #cve #win #sigma #rules
@ptescalator
More in General
- We helped Apple fix a vulnerability in the kernel of its operating systems
We helped Apple fix a vulnerability in the kernel of its operating systems PT ESC expert…
- Recovering EVTX records: carving methods
Recovering EVTX records: carving methods 🧩 When investigating incidents where attackers encrypt virtual machine images, a…
- Operation Chewbacca
At the end of June, the PT ESC team, during incident investigations, discovered a new group…
- Your Zimbra server is at risk
Recently, our PT ESC IR team encountered a new attack by ransomware groups on Zimbra mail…
- He's not your gsocket
He's not gsocket to you 😑 During the investigation of one of the incidents, PT ESC…







