CVE-2025-55234
Windows SMB Elevation of Privilege Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
SMB Server might be susceptible to relay attacks depending on the configuration. An attacker who successfully exploited these vulnerabilities could perform relay attacks and make the users subject to elevation of privilege attacks.
The SMB Server already supports mechanisms for hardening against relay attacks: SMB Server signing
SMB Server Extended Protection for Authentication (EPA) Microsoft is releasing this CVE to provide customers with audit capabilities to help them to assess their environment and to identify any potential device or software incompatibility issues before deploying SMB Server hardening measures that protect against relay attacks.
If you have not already enabled SMB Server hardening measures, we advise customers to take the following actions to be protected from these relay attacks: Assess your environment by utilizing the audit capabilities that we are exposing in the September 2025 security updates. See Support for Audit Events to deploy SMB Server Hardening—SMB Server Signing & SMB Server EPA.
Adopt appropriate SMB Server hardening measures.
SMB Server might be susceptible to relay attacks depending on the configuration. An attacker who successfully exploited these vulnerabilities could perform relay attacks and make the users subject to elevation of privilege attacks. The SMB Server already supports mechanisms for hardening against relay attacks: SMB Server signing SMB Server Extended Protection for Authentication (EPA) Microsoft is releasing this CVE to provide customers with audit capabilities to help them to assess their environment and to identify any potential device or software incompatibility issues before deploying SMB Server hardening measures that protect against relay attacks. If you have not already enabled SMB Server hardening measures, we advise customers to take the following actions to be protected from these relay attacks: Assess your environment by utilizing the audit capabilities that we are exposing in the September 2025 security updates. See Support for Audit Events to deploy SMB Server Hardening—SMB Server Signing & SMB Server EPA. Adopt appropriate SMB Server hardening measures.
CVSS Scores
SSVC
- Decision:Track*
Timeline
- 2025-08-11 CVE Reserved
- 2025-09-09 CVE Published
- 2025-09-12 CVE Updated
- 2025-09-15 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-287: Improper Authentication
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-55234 | 2025-09-12 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Microsoft Search vendor "Microsoft" | Windows 10 Version 1809 Search vendor "Microsoft" for product "Windows 10 Version 1809" | >= 10.0.17763.0 < 10.0.17763.7792 Search vendor "Microsoft" for product "Windows 10 Version 1809" and version " >= 10.0.17763.0 < 10.0.17763.7792" | en |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Windows Server 2019 Search vendor "Microsoft" for product "Windows Server 2019" | >= 10.0.17763.0 < 10.0.17763.7792 Search vendor "Microsoft" for product "Windows Server 2019" and version " >= 10.0.17763.0 < 10.0.17763.7792" | en |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Windows Server 2019 (Server Core Installation) Search vendor "Microsoft" for product "Windows Server 2019 (Server Core Installation)" | >= 10.0.17763.0 < 10.0.17763.7792 Search vendor "Microsoft" for product "Windows Server 2019 (Server Core Installation)" and version " >= 10.0.17763.0 < 10.0.17763.7792" | en |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Windows Server 2022 Search vendor "Microsoft" for product "Windows Server 2022" | >= 10.0.20348.0 < 10.0.20348.4171 Search vendor "Microsoft" for product "Windows Server 2022" and version " >= 10.0.20348.0 < 10.0.20348.4171" | en |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Windows 10 Version 21H2 Search vendor "Microsoft" for product "Windows 10 Version 21H2" | >= 10.0.19044.0 < 10.0.19044.6332 Search vendor "Microsoft" for product "Windows 10 Version 21H2" and version " >= 10.0.19044.0 < 10.0.19044.6332" | en |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Windows 11 Version 22H2 Search vendor "Microsoft" for product "Windows 11 Version 22H2" | >= 10.0.22621.0 < 10.0.22621.5909 Search vendor "Microsoft" for product "Windows 11 Version 22H2" and version " >= 10.0.22621.0 < 10.0.22621.5909" | en |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Windows 10 Version 22H2 Search vendor "Microsoft" for product "Windows 10 Version 22H2" | >= 10.0.19045.0 < 10.0.19045.6332 Search vendor "Microsoft" for product "Windows 10 Version 22H2" and version " >= 10.0.19045.0 < 10.0.19045.6332" | en |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Windows Server 2025 (Server Core Installation) Search vendor "Microsoft" for product "Windows Server 2025 (Server Core Installation)" | >= 10.0.26100.0 < 10.0.26100.6584 Search vendor "Microsoft" for product "Windows Server 2025 (Server Core Installation)" and version " >= 10.0.26100.0 < 10.0.26100.6584" | en |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Windows 11 Version 22H3 Search vendor "Microsoft" for product "Windows 11 Version 22H3" | >= 10.0.22631.0 < 10.0.22631.5909 Search vendor "Microsoft" for product "Windows 11 Version 22H3" and version " >= 10.0.22631.0 < 10.0.22631.5909" | en |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Windows 11 Version 23H2 Search vendor "Microsoft" for product "Windows 11 Version 23H2" | >= 10.0.22631.0 < 10.0.22631.5909 Search vendor "Microsoft" for product "Windows 11 Version 23H2" and version " >= 10.0.22631.0 < 10.0.22631.5909" | en |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Windows Server 2022, 23H2 Edition (Server Core Installation) Search vendor "Microsoft" for product "Windows Server 2022, 23H2 Edition (Server Core Installation)" | >= 10.0.25398.0 < 10.0.25398.1849 Search vendor "Microsoft" for product "Windows Server 2022, 23H2 Edition (Server Core Installation)" and version " >= 10.0.25398.0 < 10.0.25398.1849" | en |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Windows 11 Version 24H2 Search vendor "Microsoft" for product "Windows 11 Version 24H2" | >= 10.0.26100.0 < 10.0.26100.6584 Search vendor "Microsoft" for product "Windows 11 Version 24H2" and version " >= 10.0.26100.0 < 10.0.26100.6584" | en |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Windows Server 2025 Search vendor "Microsoft" for product "Windows Server 2025" | >= 10.0.26100.0 < 10.0.26100.6584 Search vendor "Microsoft" for product "Windows Server 2025" and version " >= 10.0.26100.0 < 10.0.26100.6584" | en |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Windows 10 Version 1507 Search vendor "Microsoft" for product "Windows 10 Version 1507" | >= 10.0.10240.0 < 10.0.10240.21128 Search vendor "Microsoft" for product "Windows 10 Version 1507" and version " >= 10.0.10240.0 < 10.0.10240.21128" | en |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Windows 10 Version 1607 Search vendor "Microsoft" for product "Windows 10 Version 1607" | >= 10.0.14393.0 < 10.0.14393.8422 Search vendor "Microsoft" for product "Windows 10 Version 1607" and version " >= 10.0.14393.0 < 10.0.14393.8422" | en |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Windows Server 2016 Search vendor "Microsoft" for product "Windows Server 2016" | >= 10.0.14393.0 < 10.0.14393.8422 Search vendor "Microsoft" for product "Windows Server 2016" and version " >= 10.0.14393.0 < 10.0.14393.8422" | en |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Windows Server 2016 (Server Core Installation) Search vendor "Microsoft" for product "Windows Server 2016 (Server Core Installation)" | >= 10.0.14393.0 < 10.0.14393.8422 Search vendor "Microsoft" for product "Windows Server 2016 (Server Core Installation)" and version " >= 10.0.14393.0 < 10.0.14393.8422" | en |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Windows Server 2008 Service Pack 2 Search vendor "Microsoft" for product "Windows Server 2008 Service Pack 2" | >= 6.0.6003.0 < 6.0.6003.23529 Search vendor "Microsoft" for product "Windows Server 2008 Service Pack 2" and version " >= 6.0.6003.0 < 6.0.6003.23529" | en |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Windows Server 2008 Service Pack 2 (Server Core Installation) Search vendor "Microsoft" for product "Windows Server 2008 Service Pack 2 (Server Core Installation)" | >= 6.0.6003.0 < 6.0.6003.23529 Search vendor "Microsoft" for product "Windows Server 2008 Service Pack 2 (Server Core Installation)" and version " >= 6.0.6003.0 < 6.0.6003.23529" | en |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Windows Server 2008 Service Pack 2 Search vendor "Microsoft" for product "Windows Server 2008 Service Pack 2" | >= 6.0.6003.0 < 6.0.6003.23529 Search vendor "Microsoft" for product "Windows Server 2008 Service Pack 2" and version " >= 6.0.6003.0 < 6.0.6003.23529" | en |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Windows Server 2008 R2 Service Pack 1 Search vendor "Microsoft" for product "Windows Server 2008 R2 Service Pack 1" | >= 6.1.7601.0 < 6.1.7601.27929 Search vendor "Microsoft" for product "Windows Server 2008 R2 Service Pack 1" and version " >= 6.1.7601.0 < 6.1.7601.27929" | en |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Windows Server 2008 R2 Service Pack 1 (Server Core Installation) Search vendor "Microsoft" for product "Windows Server 2008 R2 Service Pack 1 (Server Core Installation)" | >= 6.1.7601.0 < 6.1.7601.27929 Search vendor "Microsoft" for product "Windows Server 2008 R2 Service Pack 1 (Server Core Installation)" and version " >= 6.1.7601.0 < 6.1.7601.27929" | en |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Windows Server 2012 Search vendor "Microsoft" for product "Windows Server 2012" | >= 6.2.9200.0 < 6.2.9200.25675 Search vendor "Microsoft" for product "Windows Server 2012" and version " >= 6.2.9200.0 < 6.2.9200.25675" | en |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Windows Server 2012 (Server Core Installation) Search vendor "Microsoft" for product "Windows Server 2012 (Server Core Installation)" | >= 6.2.9200.0 < 6.2.9200.25675 Search vendor "Microsoft" for product "Windows Server 2012 (Server Core Installation)" and version " >= 6.2.9200.0 < 6.2.9200.25675" | en |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Windows Server 2012 R2 Search vendor "Microsoft" for product "Windows Server 2012 R2" | >= 6.3.9600.0 < 6.3.9600.22774 Search vendor "Microsoft" for product "Windows Server 2012 R2" and version " >= 6.3.9600.0 < 6.3.9600.22774" | en |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Windows Server 2012 R2 (Server Core Installation) Search vendor "Microsoft" for product "Windows Server 2012 R2 (Server Core Installation)" | >= 6.3.9600.0 < 6.3.9600.22774 Search vendor "Microsoft" for product "Windows Server 2012 R2 (Server Core Installation)" and version " >= 6.3.9600.0 < 6.3.9600.22774" | en |
Affected
|