home.social

#cve202533073 — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #cve202533073, aggregated by home.social.

fetched live
  1. Active Exploitation of Critical Windows SMB Flaw CVE-2025-33073 Spotted A flaw rooted in the Server Message Block (SMB) protocol of Windows enables attackers to escalate privileges to SYSTEM level ...

    #Firewall #Daily #Cyber #News #Vulnerabilities #CISA #CVE-2025-33073 #Server #Message #Block #SMB

    Origin | Interest | Match
  2. 🚨 [CISA-2025:1020] CISA Adds 5 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

    CISA has added 5 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

    ⚠️ CVE-2022-48503 (secdb.nttzen.cloud/cve/detail/)
    - Name: Apple Multiple Products Unspecified Vulnerability
    - Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
    - Known To Be Used in Ransomware Campaigns? Unknown
    - Vendor: Apple
    - Product: Multiple Products
    - Notes: support.apple.com/en-us/HT2133 ; support.apple.com/en-us/HT2133 ; support.apple.com/en-us/HT2133 ; support.apple.com/en-us/HT2133 ; support.apple.com/en-us/HT2133 ; nvd.nist.gov/vuln/detail/CVE-2

    ⚠️ CVE-2025-2746 (secdb.nttzen.cloud/cve/detail/)
    - Name: Kentico Xperience CMS Authentication Bypass Using an Alternate Path or Channel Vulnerability
    - Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
    - Known To Be Used in Ransomware Campaigns? Unknown
    - Vendor: Kentico
    - Product: Xperience CMS
    - Notes: devnet.kentico.com/download/ho ; nvd.nist.gov/vuln/detail/CVE-2

    ⚠️ CVE-2025-2747 (secdb.nttzen.cloud/cve/detail/)
    - Name: Kentico Xperience CMS Authentication Bypass Using an Alternate Path or Channel Vulnerability
    - Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
    - Known To Be Used in Ransomware Campaigns? Unknown
    - Vendor: Kentico
    - Product: Xperience CMS
    - Notes: devnet.kentico.com/download/ho ; nvd.nist.gov/vuln/detail/CVE-2

    ⚠️ CVE-2025-33073 (secdb.nttzen.cloud/cve/detail/)
    - Name: Microsoft Windows SMB Client Improper Access Control Vulnerability
    - Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
    - Known To Be Used in Ransomware Campaigns? Unknown
    - Vendor: Microsoft
    - Product: Windows
    - Notes: msrc.microsoft.com/update-guid ; nvd.nist.gov/vuln/detail/CVE-2

    ⚠️ CVE-2025-61884 (secdb.nttzen.cloud/cve/detail/)
    - Name: Oracle E-Business Suite Server-Side Request Forgery (SSRF) Vulnerability
    - Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
    - Known To Be Used in Ransomware Campaigns? Unknown
    - Vendor: Oracle
    - Product: E-Business Suite
    - Notes: oracle.com/security-alerts/ale ; nvd.nist.gov/vuln/detail/CVE-2

    #SecDB #InfoSec #CVE #CISA_KEV #cisa_20251020 #cisa20251020 #cve_2022_48503 #cve_2025_2746 #cve_2025_2747 #cve_2025_33073 #cve_2025_61884 #cve202248503 #cve20252746 #cve20252747 #cve202533073 #cve202561884

  3. A new Windows SMB flaw may be the weak link in your network’s armor—attackers are already exploiting it for full control. Are you ready to close this dangerous gap before it’s too late?

    thedefendopsdiaries.com/unders

    #cve202533073
    #windowsvulnerability
    #smbflaw
    #cybersecurity
    #patchmanagement

  4. Reflective Kerberos Relay Attack (CVE-2025-33073): NT AUTHORITY\SYSTEM Privilege Escalation How the Reflective Kerberos Relay Attack Bypassed NTLM Protections in 2025 (CVE-2025-33073) . Reflective ...

    #kerberos-relay-attack #red-team #privilege-escalation #cve-2025-33073 #smb-authentication-bypass

    Origin | Interest | Match
Share on Mastodon

Enter the server where you have an account.