# Windows SMB Kerberos reflection elevation of privilege

Source: https://startwithidentity.com/cves/cve-2025-33073/
Last updated: 2026-08-29
License: content by Start with Identity. Cite the source URL.

---

## What broke

Windows allowed a Kerberos authentication reflection against SMB: a service could bounce a ticket back at itself and escalate. Microsoft patched the first path. Researchers then showed Ghost SPNs (SPNs that linger after a name change or DNS self-registration) still made the pattern work. [CVE-2025-58726](https://startwithidentity.com/cves/cve-2025-58726/) is the October 2025 follow-on.

## Why it matters

Reflection plus a stale SPN is how "we patched Kerberos" still becomes domain admin. Machine identity in AD is messy: DNS updates, SPN writes, and computer accounts that outlive their names.

## What to do

- Deploy both the original fix and the October 2025 SMB/Kerberos update.
- Audit Ghost SPNs. A computer account with an SPN that no longer matches DNS is a finding, not a curiosity.
- Restrict who can write SPNs and who can register DNS names in the AD-integrated zone.

## After you patch

Active Directory compromise is not contained by patching, because the artifacts an attacker creates outlive the vulnerability.

- **Rotate the krbtgt account twice**, with the replication interval between rotations, if there is any indication of ticket forgery. One rotation is not enough.
- **Audit AD CS certificate templates** for enrolment and enrollee-supplied-subject permissions, which are the most common escalation path left behind. See [certificate lifecycle](https://startwithidentity.com/glossary/certificate-lifecycle/).
- **Review privileged group membership and delegation rights** (Domain Admins, DnsAdmins, constrained and resource-based constrained delegation) for changes during the window.
- **Hunt for tickets with anomalous lifetimes or encryption types**, and for authentications to services that identity never touches.
- **Treat any issued certificate as a durable credential**: revoking a user's password does not revoke a certificate that authenticates as them. See [privilege escalation](https://startwithidentity.com/glossary/privilege-escalation/) and [lateral movement](https://startwithidentity.com/glossary/lateral-movement/).

## Sources

- [NVD: CVE-2025-33073](https://nvd.nist.gov/vuln/detail/CVE-2025-33073)
