PT-2025-36891 · Microsoft · Smb Server +1

Published

2025-09-09

·

Updated

2025-10-26

·

CVE-2025-55234

CVSS v2.0
10
VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Windows Server Message Block (SMB) versions prior to September 2025 Patch Tuesday
Description The SMB Server may be susceptible to relay attacks depending on the configuration. Successful exploitation of this issue could allow an attacker to perform relay attacks and potentially elevate privileges. Microsoft has released audit capabilities in the September 2025 security updates to help identify potential device or software incompatibility issues before deploying SMB Server hardening measures. The vulnerability is related to flaws in the authentication procedure of the Windows SMB server.
Recommendations Assess your environment by utilizing the audit capabilities released in the September 2025 security updates. Adopt appropriate SMB Server hardening measures, including enabling SMB Server signing and SMB Server Extended Protection for Authentication (EPA).

Exploit

Fix

RCE

LPE

Improper Authentication

Weakness Enumeration

Related Identifiers

BDU:2025-10913
CVE-2025-55234

Affected Products

Smb Server
Windows