[ << ALL_FEED ]

Reflection Relay. It never happened before, and now it's happening again (CVE-2025-33073)

More in Windows

Reflection Relay. It never happened before, and now it’s happening again (CVE-2025-33073) 😐

One of the most popular techniques for privilege escalation in an Active Directory domain is Relay. For a long time, NTLM Relay attacks were well known to everyone, but not long ago several techniques were described that allow performing Relay using Kerberos. Many will understand what this is about more easily if you say SMB Relay or ADCS ESC8. But there are far more techniques for Relay attacks; they can be performed over HTTP, SMB, RPC, MSSQL, WinRMS, LDAP, and probably other protocols that will be described in the future.

If Relay attacks affect NTLM and Kerberos in combination with various protocols, how can you protect against them? In fact, there are built-in protection mechanisms that simply need to be configured. We will talk about each of them in more detail in the following posts. But today I want to focus attention on a recently discovered vulnerability — CVE-2025-33073.

❗️ First, a bit about the vulnerability itself. Exploitation occurs in conjunction with a Relay attack — whether Kerberos or NTLM. Its roots go back to 2008. That year, Microsoft released security bulletin MS08-068, after which the Relay technique stopped working when a computer attacked itself.

At that time, techniques like Coerce were not yet widely known, but shortcuts were already actively used (for example, LNK files that hackers scattered in writable SMB shared folders) to obtain an administrator session on a device and perform a Relay attack against it to escalate privileges. We will call such a Relay Reflective.

Since then, coercion techniques have appeared — Coerce — and Relay attacks themselves have become more sophisticated, but there was no Reflective Relay specifically over the network. But then 2021 arrives, and a study appears online that describes in considerable detail the mechanism of Kerberos authentication, including on an SMB server. There is no point in repeating it; it is enough to say that it is there that a strange host name first appears:

fileserver1UWhRCAAAAAAAAAAUAAAAAAAAAAAAAAAAAAAAAfileserversBAAA

In addition, the author rightly notes that a string of this kind could well be a DNS record. Despite the fundamental nature of the research, no vulnerabilities were found in the mechanism.

🗓 Then 2025 arrives, and on June 11 two studies are released one after another: the first and the second. They are closely related to each other and are based on the 2021 research, so it is best to read them in exactly that order. These studies demonstrate the possibility of Reflective Relay for both NTLM and Kerberos.

About the exploitation of CVE-2025-33073 in the post below👇

#cve #win #offensive
@ptescalator

More from global_author

More from global_author

More in Windows