CVE-2025-33073Windows SMB Kerberos reflection elevation of privilege
What broke
Windows allowed a Kerberos authentication reflection against SMB: a service could bounce a ticket back at itself and escalate. Microsoft patched the first path. Researchers then showed Ghost SPNs (SPNs that linger after a name change or DNS self-registration) still made the pattern work. CVE-2025-58726 is the October 2025 follow-on.
Why it matters
Reflection plus a stale SPN is how "we patched Kerberos" still becomes domain admin. Machine identity in AD is messy: DNS updates, SPN writes, and computer accounts that outlive their names.
What to do
- Deploy both the original fix and the October 2025 SMB/Kerberos update.
- Audit Ghost SPNs. A computer account with an SPN that no longer matches DNS is a finding, not a curiosity.
- Restrict who can write SPNs and who can register DNS names in the AD-integrated zone.
After you patch
Active Directory compromise is not contained by patching, because the artifacts an attacker creates outlive the vulnerability.
- Rotate the krbtgt account twice, with the replication interval between rotations, if there is any indication of ticket forgery. One rotation is not enough.
- Audit AD CS certificate templates for enrolment and enrollee-supplied-subject permissions, which are the most common escalation path left behind. See certificate lifecycle.
- Review privileged group membership and delegation rights (Domain Admins, DnsAdmins, constrained and resource-based constrained delegation) for changes during the window.
- Hunt for tickets with anomalous lifetimes or encryption types, and for authentications to services that identity never touches.
- Treat any issued certificate as a durable credential: revoking a user's password does not revoke a certificate that authenticates as them. See privilege escalation and lateral movement.
Sources
Related identity CVEs
Related on Start with Identity
- CVEWindows Kerberos elevation of privilege
A 2026 Windows Kerberos elevation of privilege, patched by Microsoft. High severity. Read it next to KerberLoss and ResetNightmare: the 2026 AD year is a Kerber
- CVEWindows Kerberos information disclosure
A medium-severity Kerberos information-disclosure in Windows. Not a domain-compromise bug on its own, but it sits in the same 2025 Kerberos patch train as the S
- CVEWindows Kerberos PAC validation in cross-forest scenarios
The forest-trust sibling of CVE-2024-26248. PAC validation could be skipped across a trust. Same April 2024 patch train, same staged enforcement.
- BlogKerberLoss: invisible Unicode lets an attacker twin a Kerberos SPN
CVE-2026-25177, CVSS 8.8. Active Directory treated look-alike SPNs as unique. Semperis and Shai Laron showed how that becomes service hijack and NTLM downgrade.
- BlogA CVE ID is a name. The value is knowing who the attacker becomes.
We opened a practitioner catalog of identity CVEs: what broke, why IAM teams should care, and what to do this week. Not an NVD mirror. A place to triage SAML wr
- BlogGoogle Workspace puts FIDO2 keys into the Windows login, days after Entra makes passkeys default
Google began rolling out FIDO2 security keys as a second factor at Windows sign-in for all Workspace customers on 13 July. Microsoft is making passkeys the defa
Technique
This CVE is an instance of Kerberos delegation abuse. Delegation lets a service act as the user who called it, which is necessary for multi-tier applications and dangerous the moment the service or the delegation scope is not exactly what an administrator intended.