authentication reflection

  1. Synacktiv Bypasses CVE-2025-33073 Mitigation for SYSTEM Shells on Patched Windows Server

    A newly published Synacktiv proof-of-concept shows how attackers could bypass Microsoft’s CVE-2025-33073 mitigation and obtain NT AUTHORITY\SYSTEM shells on patched Windows Server 2025 systems by abusing SMB authentication reflection over arbitrary TCP ports before Microsoft patched the...