Improper access control in Windows SMB allows an authorized attacker to elevate privileges over a network.
https://www.cisa.gov/sites/default/files/2026-08/cisa-vulnerability-review-fy-2024-2025.pdf
https://securelist.com/vulnerabilities-and-exploits-in-q2-2026/121091/
https://unit42.paloaltonetworks.com/the-gentlemen-ransomware/
https://www.theregister.com/2025/10/21/cisa_windows_smb_bug/
https://www.databreachtoday.com/cisa-flags-highly-exploitable-windows-smb-flaw-a-29778
https://thehackernews.com/2025/10/five-new-exploited-bugs-land-in-cisas.html
https://www.guidepointsecurity.com/blog/the-birth-and-death-of-loopyticket/
https://www.databreachtoday.com/breach-roundup-critical-rce-flaw-in-roundcube-servers-a-28680
https://www.infosecurity-magazine.com/news/two-microsoft-zero-days-june-patch/
https://thehackernews.com/2025/06/microsoft-patches-67-vulnerabilities.html
https://blog.redteam-pentesting.de/2025/reflective-kerberos-relay-attack/
https://github.com/0xNDI/cvedetect
https://github.com/jonaslejon/ad-autopwn
https://github.com/IyarGross/SMB-CVE-2025-33073
https://github.com/EgCupCake/cupntlm-Automated-Exploit-For-CVE-2025-33073-
https://github.com/pol4ir/CVE-2025-33073
https://github.com/Iddygodwin/CVE-2025-33073
https://github.com/32BitZ-Studio/Total-POC-CVE
https://github.com/PuddinCat/GithubRepoSpider
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-33073
Published: 2025-06-10
Updated: 2025-10-27
Named Vulnerability: LoopyTicketKnown Exploited Vulnerability (KEV)
Base Score: 9
Vector: CVSS2#AV:N/AC:L/Au:S/C:C/I:C/A:C
Severity: High
Base Score: 8.8
Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Severity: High
EPSS: 0.82699
Tenable Research has classified this CVE under the following Vulnerability Watch classification, which includes active and historical (inactive) classifications. You can learn more about these classifications on our blog.
Vulnerability Being Monitored