CVE-2025-53778
massImproper Authentication in Microsoft Windows NTLM Enables Privilege Escalation
CVE-2025-53778 is an improper authentication vulnerability (CWE-287) in the NTLM authentication implementation in Microsoft Windows, addressed as part of Microsoft's August 2025 Patch Tuesday release. An attacker who already holds valid low-privileged credentials can trigger the flaw by authenticating over the network to a vulnerable Windows host, causing the authentication check to be bypassed or mishandled. Successful exploitation results in elevation of privilege on the targeted system, with high impact on confidentiality, integrity, and availability. Affected systems span essentially all mainstream Windows releases in the data: Windows 10 (1507 through 22H2), Windows 11 (22H2 through 24H2), and Windows Server 2008 through 2019. No public proof-of-concept or confirmed in-the-wild exploitation is known and it is not in CISA KEV, but a high EPSS (38.9% probability of exploitation within 30 days, 98th percentile) indicates an elevated likelihood of exploitation in the near term.
What to do: Apply Microsoft's August 2025 security updates for all affected Windows 10, Windows 11, and Windows Server versions as soon as possible, prioritizing domain controllers, file servers, and other network-facing systems given the elevated EPSS. Audit NTLM usage in the environment and restrict or disable NTLM where Kerberos authentication is available, since the flaw resides in NTLM. Because exploitation requires valid credentials, review accounts with network logon rights and monitor for anomalous authenticated activity.
| microsoft Windows 10 | 1507, 1607, 1809, 21H2, 22H2 |
| microsoft Windows 11 | 22H2, 23H2, 24H2 |
| microsoft Windows Server 2008 | 2008 |
| microsoft Windows Server 2012 | 2012 |
| microsoft Windows Server 2016 | 2016 |
| microsoft Windows Server 2019 | 2019 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Improper authentication in Windows NTLM allows an authorized attacker to elevate privileges over a network.
- Vendors
- microsoft
- Products
- windows 10 1507, windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 22h2, windows 11 23h2, windows 11 24h2, windows server 2008, windows server 2012, windows server 2016, windows server 2019
- Weakness
- CWE-287
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H