CISA Warns of Active Exploitation of Critical Windows SMB Flaw CVE-2025-33073 https://thecyberexpress.com/windows-smb-flaw-cve-2025-33073-alert/ #TheCyberExpressNews #ServerMessageBlock #Vulnerabilities #TheCyberExpress #FirewallDaily #CVE202533073 #CyberNews #Windows #CISA #SMB
#cve202533073 — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #cve202533073, aggregated by home.social.
-
Active Exploitation of Critical Windows SMB Flaw CVE-2025-33073 Spotted A flaw rooted in the Server Message Block (SMB) protocol of Windows enables attackers to escalate privileges to SYSTEM level ...
#Firewall #Daily #Cyber #News #Vulnerabilities #CISA #CVE-2025-33073 #Server #Message #Block #SMB
Origin | Interest | Match -
🚨 [CISA-2025:1020] CISA Adds 5 Known Exploited Vulnerabilities to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2025:1020)
CISA has added 5 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.
⚠️ CVE-2022-48503 (https://secdb.nttzen.cloud/cve/detail/CVE-2022-48503)
- Name: Apple Multiple Products Unspecified Vulnerability
- Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Apple
- Product: Multiple Products
- Notes: https://support.apple.com/en-us/HT213340 ; https://support.apple.com/en-us/HT213341 ; https://support.apple.com/en-us/HT213342 ; https://support.apple.com/en-us/HT213345 ; https://support.apple.com/en-us/HT213346 ; https://nvd.nist.gov/vuln/detail/CVE-2022-48503⚠️ CVE-2025-2746 (https://secdb.nttzen.cloud/cve/detail/CVE-2025-2746)
- Name: Kentico Xperience CMS Authentication Bypass Using an Alternate Path or Channel Vulnerability
- Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Kentico
- Product: Xperience CMS
- Notes: https://devnet.kentico.com/download/hotfixes ; https://nvd.nist.gov/vuln/detail/CVE-2025-2746⚠️ CVE-2025-2747 (https://secdb.nttzen.cloud/cve/detail/CVE-2025-2747)
- Name: Kentico Xperience CMS Authentication Bypass Using an Alternate Path or Channel Vulnerability
- Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Kentico
- Product: Xperience CMS
- Notes: https://devnet.kentico.com/download/hotfixes ; https://nvd.nist.gov/vuln/detail/CVE-2025-2747⚠️ CVE-2025-33073 (https://secdb.nttzen.cloud/cve/detail/CVE-2025-33073)
- Name: Microsoft Windows SMB Client Improper Access Control Vulnerability
- Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Microsoft
- Product: Windows
- Notes: https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2025-33073 ; https://nvd.nist.gov/vuln/detail/CVE-2025-33073⚠️ CVE-2025-61884 (https://secdb.nttzen.cloud/cve/detail/CVE-2025-61884)
- Name: Oracle E-Business Suite Server-Side Request Forgery (SSRF) Vulnerability
- Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Oracle
- Product: E-Business Suite
- Notes: https://www.oracle.com/security-alerts/alert-cve-2025-61884.html ; https://nvd.nist.gov/vuln/detail/CVE-2025-61884#SecDB #InfoSec #CVE #CISA_KEV #cisa_20251020 #cisa20251020 #cve_2022_48503 #cve_2025_2746 #cve_2025_2747 #cve_2025_33073 #cve_2025_61884 #cve202248503 #cve20252746 #cve20252747 #cve202533073 #cve202561884
-
A new Windows SMB flaw may be the weak link in your network’s armor—attackers are already exploiting it for full control. Are you ready to close this dangerous gap before it’s too late?
#cve202533073
#windowsvulnerability
#smbflaw
#cybersecurity
#patchmanagement -
Reflective Kerberos Relay Attack (CVE-2025-33073): NT AUTHORITY\SYSTEM Privilege Escalation How the Reflective Kerberos Relay Attack Bypassed NTLM Protections in 2025 (CVE-2025-33073) . Reflective ...
#kerberos-relay-attack #red-team #privilege-escalation #cve-2025-33073 #smb-authentication-bypass
Origin | Interest | Match -
Patch Tuesday, June 2025 Edition https://krebsonsecurity.com/2025/06/patch-tuesday-june-2025-edition/ #WindowsServerMessageBlock #sansinternetstormcenter #PatchTuesdayJune2025 #ExperienceManager #mozillafirefox #SecurityTools #AcrobatReader #BadSuccessor #CVE202533053 #CVE202533073 #GoogleChrome #TimetoPatch #AdamBarnett #AlexVovk #SethHoyt #Action1 #Automox #Akamai #Rapid7 #WebDAV