PT-2025-36891 · Microsoft · Smb Server+1
Published
2025-09-09
·
Updated
2026-03-10
·
CVE-2025-55234
CVSS v3.1
10
Critical
| AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Windows Server Message Block (SMB) versions prior to September 2025 Patch Tuesday
Description
The SMB Server may be susceptible to relay attacks depending on the configuration. Successful exploitation of this issue could allow an attacker to perform relay attacks and potentially elevate privileges. Microsoft has released audit capabilities in the September 2025 security updates to help identify potential device or software incompatibility issues before deploying SMB Server hardening measures. The vulnerability is related to flaws in the authentication procedure of the Windows SMB server.
Recommendations
Assess your environment by utilizing the audit capabilities released in the September 2025 security updates.
Adopt appropriate SMB Server hardening measures, including enabling SMB Server signing and SMB Server Extended Protection for Authentication (EPA).
Exploit
Fix
LPE
RCE
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Smb Server
Windows