Federal cybersecurity officials confirm active exploitation of a high-severity Windows SMB vulnerability months after Microsoft released patches. The flaw, rated 8.8 on the CVSS scale, enables attackers to escalate privileges and move laterally within compromised networks. Organizations are urged to apply June 2025 security updates immediately.
Active Exploitation Confirmed
The Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that a high-severity vulnerability in Microsoft’s Windows SMB client is now being actively exploited in the wild, according to reports. The flaw, tracked as CVE-2025-33073, was added to CISA’s Known Exploited Vulnerabilities catalog on October 20, indicating that threat actors are successfully leveraging the vulnerability in ongoing campaigns despite patches being available since June 2025.