Direct naar de inhoud
Kritieke cyberalerts voor jouw sector & systemen — direct in je inbox. Aanmelden →
CVE's Videos

← Terug naar CVE-database

CVE-2025-33073

CRITICAL · 9.5 CVSS Gepubliceerd: CWE-284

Beschrijving NL

Microsoft Windows SMB Client bevat een onjuist beveiligingslek voor toegangscontrole dat kan leiden tot privilege-escalatie. Een aanvaller kan een speciaal vervaardigd kwaadaardig script uitvoeren om de slachtoffermachine te dwingen om met behulp van SMB verbinding te maken met het aanvalssysteem en zich te authenticeren.

Vereiste actie: pas mitigaties toe volgens de instructies van de leverancier, volg de toepasselijke BOD 22-01-richtlijnen voor cloudservices of stop het gebruik van het product als er geen mitigaties beschikbaar zijn.

Origineel (Engels) tonen

Microsoft Windows SMB Client contains an improper access control vulnerability that could allow for privilege escalation. An attacker could execute a specially crafted malicious script to coerce the victim machine to connect back to the attack system using SMB and authenticate.

Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Vendors

Microsoft

Affected products

Windows

References