ZeroHour

CVE-2025-53778

mass

Improper Authentication in Microsoft Windows NTLM Enables Privilege Escalation

CVSS 3.1
8.8 high
EPSS
39%p98
Published
()
Modified
AI analysis

CVE-2025-53778 is an improper authentication vulnerability (CWE-287) in the NTLM authentication implementation in Microsoft Windows, addressed as part of Microsoft's August 2025 Patch Tuesday release. An attacker who already holds valid low-privileged credentials can trigger the flaw by authenticating over the network to a vulnerable Windows host, causing the authentication check to be bypassed or mishandled. Successful exploitation results in elevation of privilege on the targeted system, with high impact on confidentiality, integrity, and availability. Affected systems span essentially all mainstream Windows releases in the data: Windows 10 (1507 through 22H2), Windows 11 (22H2 through 24H2), and Windows Server 2008 through 2019. No public proof-of-concept or confirmed in-the-wild exploitation is known and it is not in CISA KEV, but a high EPSS (38.9% probability of exploitation within 30 days, 98th percentile) indicates an elevated likelihood of exploitation in the near term.

What to do: Apply Microsoft's August 2025 security updates for all affected Windows 10, Windows 11, and Windows Server versions as soon as possible, prioritizing domain controllers, file servers, and other network-facing systems given the elevated EPSS. Audit NTLM usage in the environment and restrict or disable NTLM where Kerberos authentication is available, since the flaw resides in NTLM. Because exploitation requires valid credentials, review accounts with network logon rights and monitor for anomalous authenticated activity.

Affected
microsoft Windows 101507, 1607, 1809, 21H2, 22H2
microsoft Windows 1122H2, 23H2, 24H2
microsoft Windows Server 20082008
microsoft Windows Server 20122012
microsoft Windows Server 20162016
microsoft Windows Server 20192019
Estimated exposure
masswell over 1 billion Windows 10/11 client and Windows Server installations are potentially in scope (near-total coverage of the Windows installed base) — The affected list spans every mainstream Windows 10/11 client branch and widely deployed Windows Server versions from 2008 through 2019, which together cover the overwhelming majority of Microsoft's >1.4 billion-device Windows installed…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Improper authentication in Windows NTLM allows an authorized attacker to elevate privileges over a network.

Vendors
microsoft
Products
windows 10 1507, windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 22h2, windows 11 23h2, windows 11 24h2, windows server 2008, windows server 2012, windows server 2016, windows server 2019
Weakness
CWE-287
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news