Remote Code Execution Flaw in Windows KDC Proxy Service Exposes Systems
CVE-2025-33071
What is CVE-2025-33071?
A vulnerability in the Windows KDC Proxy Service (KPSSVC) allows unauthorized users to execute arbitrary code across a network due to a use after free scenario. This flaw could lead to significant security risks if exploited, enabling an attacker to potentially gain control over affected systems remotely. Regular updates and vulnerability management are essential to mitigate this risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Windows Server 2012 (Server Core installation) x64-based Systems 6.2.9200.0 < 6.2.9200.25522
Windows Server 2012 R2 (Server Core installation) x64-based Systems 6.3.9600.0 < 6.3.9600.22620
Windows Server 2012 R2 x64-based Systems 6.3.9600.0 < 6.3.9600.22620
News Articles
References
CVSS V3.1
Timeline
- ๐ฐ
First article discovered by The Hacker News
Vulnerability published
Vulnerability Reserved