Exploitation of CVE-2025-33073

More in Windows
- This is Siemens...
Recently, our colleagues from the Positive Industrial Expertise Center discovered a curious Windows sample on MalwareBazaar.…
- A look inside ESE
Looking inside ESE 🫣 During incident investigations, we at PT ESC IR regularly encounter the need…
- ::%16777216 — so what exactly are you?
::%16777216 — so what exactly are you? It is known that during attacks, adversaries can use…
- Confusion in WSUS vulnerabilities: setting the record straight
Confusion Around WSUS Vulnerabilities: Setting the Record Straight 🕷 One of the most pressing vulnerabilities in…
- Disabling Defender / MpPreference
In addition to the post 👆 Disabling Defender / MpPreference Set-MpPreference -DisableRealtimeMonitoring $true Set-MpPreference -DisableBehaviorMonitoring $true…
🧤 Now about the exploitation of the vulnerability CVE-2025-33073:
• A domain account with the most ordinary privileges.
• SMB signing is not enforced on the targeted device.
• The targeted device does not have the patch that fixes the CVE-2025-33073 vulnerability, which was released in June 2025.
And additionally, one of the two:
• Either the ability to register a DNS record in the domain (by default, all domain users can do this).
• Or being on the same broadcast network as the targeted device (conducting NBNS, LLMNR, and mDNS spoofing attacks).
Let’s look at two exploitation scenarios with dumping local credentials from SAM and SECURITY.
1️⃣ First scenario with a DNS record (screenshot 1):
1. The attacker registers a DNS record in the format localhost1UWhRCAAAAAAAAAAAAAAAAAAAAAAAAAAAAwbEAYBAAAA
2. The attacker performs a Coerce attack on the device without SMB Signing.
3. The device resolves the name via DNS, in which it receives the attacker’s IP address.
4. The device authenticates to the attacker’s server.
5. The attacker performs a Relay attack on the same device, obtains an authenticated session with SYSTEM privileges.
2️⃣ Second scenario with spoofing (screenshot 2):
1. The attacker launches spoofing with a response to the hostname localhost1UWhRCAAAAAAAAAAAAAAAAAAAAAAAAAAAAwbEAYBAAAA
2. The attacker performs a Coerce attack on the device on the local network.
3. The device attempts to resolve the name via DNS, does not find it, and moves on to multicast protocols.
4. The attacker tells the device that the name belongs to them.
5. The device authenticates to the attacker’s server.
6. The attacker performs a Relay attack on the same device, obtains an authenticated session with SYSTEM privileges.
Instead of a conclusion, I would like to emphasize that this vulnerability was the result of many years of research by several specialists and, likely, could have been discovered and used by someone earlier. No one knows how many more such vulnerabilities will be discovered. But in this case, as in most others, by applying best security practices in advance, you can avoid serious consequences when such vulnerabilities appear, even without installing the update.
Recommendations for protection against the vulnerability:
• Install the security updates from June 10, 2025.
• Configure enforcement of SMB signing for SMB services on controllers and workstations.
In the following posts, we’ll tell you how to detect the vulnerability 😉

#cve #win #offensive
@ptescalator
More in Windows
- This is Siemens...
Recently, our colleagues from the Positive Industrial Expertise Center discovered a curious Windows sample on MalwareBazaar.…
- A look inside ESE
Looking inside ESE 🫣 During incident investigations, we at PT ESC IR regularly encounter the need…
- ::%16777216 — so what exactly are you?
::%16777216 — so what exactly are you? It is known that during attacks, adversaries can use…
- Confusion in WSUS vulnerabilities: setting the record straight
Confusion Around WSUS Vulnerabilities: Setting the Record Straight 🕷 One of the most pressing vulnerabilities in…
- Disabling Defender / MpPreference
In addition to the post 👆 Disabling Defender / MpPreference Set-MpPreference -DisableRealtimeMonitoring $true Set-MpPreference -DisableBehaviorMonitoring $true…





