[ << ALL_FEED ]

Exploitation of CVE-2025-33073

More in Windows

🧤 Now about the exploitation of the vulnerability CVE-2025-33073:

• A domain account with the most ordinary privileges.
• SMB signing is not enforced on the targeted device.
• The targeted device does not have the patch that fixes the CVE-2025-33073 vulnerability, which was released in June 2025.

And additionally, one of the two:

• Either the ability to register a DNS record in the domain (by default, all domain users can do this).
• Or being on the same broadcast network as the targeted device (conducting NBNS, LLMNR, and mDNS spoofing attacks).

Let’s look at two exploitation scenarios with dumping local credentials from SAM and SECURITY.

1️⃣ First scenario with a DNS record (screenshot 1):

1. The attacker registers a DNS record in the format localhost1UWhRCAAAAAAAAAAAAAAAAAAAAAAAAAAAAwbEAYBAAAA

2. The attacker performs a Coerce attack on the device without SMB Signing.

3. The device resolves the name via DNS, in which it receives the attacker’s IP address.

4. The device authenticates to the attacker’s server.

5. The attacker performs a Relay attack on the same device, obtains an authenticated session with SYSTEM privileges.

2️⃣ Second scenario with spoofing (screenshot 2):

1. The attacker launches spoofing with a response to the hostname localhost1UWhRCAAAAAAAAAAAAAAAAAAAAAAAAAAAAwbEAYBAAAA

2. The attacker performs a Coerce attack on the device on the local network.

3. The device attempts to resolve the name via DNS, does not find it, and moves on to multicast protocols.

4. The attacker tells the device that the name belongs to them.

5. The device authenticates to the attacker’s server.

6. The attacker performs a Relay attack on the same device, obtains an authenticated session with SYSTEM privileges.

Instead of a conclusion, I would like to emphasize that this vulnerability was the result of many years of research by several specialists and, likely, could have been discovered and used by someone earlier. No one knows how many more such vulnerabilities will be discovered. But in this case, as in most others, by applying best security practices in advance, you can avoid serious consequences when such vulnerabilities appear, even without installing the update.

Recommendations for protection against the vulnerability:

• Install the security updates from June 10, 2025.

• Configure enforcement of SMB signing for SMB services on controllers and workstations.

In the following posts, we’ll tell you how to detect the vulnerability 😉

#cve #win #offensive
@ptescalator

More from global_author

More from global_author

More in Windows