SMB Server Vulnerability Impacts Microsoft Products
CVE-2025-55234

8.8HIGH

What is CVE-2025-55234?

The SMB Server vulnerability allows an attacker to exploit relay configurations, potentially leading to elevation of privilege attacks. Microsoft emphasizes the importance of implementing hardening measures such as SMB Server signing and Extended Protection for Authentication (EPA). To mitigate risks, organizations should utilize the audit capabilities provided in the September 2025 security updates and assess their environments for any potential incompatibility issues. Enabling these protective measures is crucial for safeguarding against relay attacks.

Affected Version(s)

Windows 10 Version 1507 32-bit Systems 10.0.10240.0 < 10.0.10240.21128

Windows 10 Version 1607 32-bit Systems 10.0.14393.0 < 10.0.14393.8422

Windows 10 Version 1809 32-bit Systems 10.0.17763.0 < 10.0.17763.7792

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-55234 : SMB Server Vulnerability Impacts Microsoft Products