Skip to content

PoC Released for NTLM reflection bypass Vulnerability that Emanbles SYSTEM Access on Windows Server

Gbhackers Mayura Kathir June 30, 2026

A proof-of-concept has been published that bypasses Microsoft’s mitigation for the NTLM reflection vulnerability tracked as CVE-2025-33073 and allows escalation to NT AUTHORITY\SYSTEM on Windows Server. The exploit leverages two conceptual weaknesses left unaddressed by the original patch: the mitigation was limited to the SMB client path, and recent SMB features let attackers coerce privileged […]