CVE-2025-58726

Published Oct 14, 2025

Last updated 5 months ago

Overview

Description
Improper access control in Windows SMB Server allows an authorized attacker to elevate privileges over a network.
Source
secure@microsoft.com
NVD status
Modified
Products
windows_10_1507, windows_10_1607, windows_10_1809, windows_10_21h2, windows_10_22h2, windows_11_22h2, windows_11_23h2, windows_11_24h2, windows_11_25h2, windows_server_2008, windows_server_2012, windows_server_2016, windows_server_2019, windows_server_2022, windows_server_2022_23h2, windows_server_2025

Risk scores

CVSS 3.1

Type
Secondary
Base score
7.5
Impact score
5.9
Exploitability score
1.6
Vector string
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Severity
HIGH

Weaknesses

secure@microsoft.com
CWE-284
nvd@nist.gov
NVD-CWE-noinfo

Social media

Hype score
Not currently trending
  1. Top 5 Trending CVEs: 1 - CVE-2004-1056 2 - CVE-2026-22812 3 - CVE-2026-20824 4 - CVE-2025-58726 5 - CVE-2025-64155 #cve #cvetrends #cveshield #cybersecurity https://t.co/4Fua3CAN6W

    @CVEShield

    19 Jan 2026

    122 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  2. #VulnerabilityReport #activedirectory Researcher Details Windows SMB Server Elevation of Privilege Vulnerability – CVE-2025-58726 https://t.co/cAGlLFVwFh

    @Komodosec

    11 Dec 2025

    10 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. CVE of the Week: Bio-Fox! 🦊 CVE-2025-58726 is a Windows SMB Server Elevation of Privilege vulnerability. It stems from improper access control and can let an authenticated attacker elevate privileges over the network. While exploitation typically requires a multi-step, comple

    @vicariusltd

    14 Nov 2025

    203 Impressions

    0 Retweets

    0 Likes

    1 Bookmark

    1 Reply

    0 Quotes

  4. ⚠️CVE-2025-58726 (Windows SMB) — Privilege Escalation Alert⚠️ CVE-2025-58726 is a vulnerability in the Windows SMB server caused by improper access controls, allowing an authenticated attacker to gain elevated privileges on the network. (CVSS: 7.5) Mitigation:Apply patc

    @CriminalIP_US

    7 Nov 2025

    389 Impressions

    2 Retweets

    2 Likes

    2 Bookmarks

    0 Replies

    0 Quotes

  5. ⚠️ CVE-2025-58726 (Windows SMB) — 권한 상승 경고 CVE-2025-58726은 Windows SMB 서버의 부적절한 접근 제어로 인해 권한 있는 공격자가 네트워크 내에서 높은 권한을 획득할 수 있는 취약점입니다(CVSS 7.5). 즉시 패치 적용, SM

    @CriminalIP_KR

    7 Nov 2025

    58 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. ⚠️CVE-2025-58726(Windows SMB) — 権限昇格の脆弱性警報​ 不適切なアクセス制御により、権限を持つ攻撃者がネットワーク内で高い権限を取得する恐れがあります。直ちにパッチ適用・SMBの外部アクセス遮断・

    @CriminalIP_JP

    6 Nov 2025

    109 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  7. WindowsのSMBサーバ権限 昇格脆弱性 CVE-2025-58726とGhost SPN/Kerberosリフレクションで権限奪取が出来る https://t.co/Fn99VM9loI #セキュリティ対策Lab #セキュリティ #Security #サイバー攻撃

    @securityLab_jp

    5 Nov 2025

    12 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. 🚨🚨CVE-2025-58726: An improper access control flaw in Windows SMB Server could allow an authorized attacker to gain elevated privileges over a network. Search by vul.cve Filter👉vul.cve="CVE-2025-58726" ZoomEye Dork👉os="windows" Over 203.9m results. ZoomEye Link: https

    @zoomeye_team

    4 Nov 2025

    9889 Impressions

    32 Retweets

    122 Likes

    47 Bookmarks

    1 Reply

    0 Quotes

  9. Windowsの新たな脆弱性「CVE-2025-58726」が公開された。攻撃者は低権限アカウントからKerberos認証の反射を悪用し、SYSTEM権限を遠隔で取得できる。この問題はSMB署名を強制していない全Windowsに影響し、Microsoftは2025

    @yousukezan

    4 Nov 2025

    935 Impressions

    0 Retweets

    10 Likes

    4 Bookmarks

    0 Replies

    0 Quotes

  10. 【Active Directory権限昇格】MicrosoftがWindows環境で深刻な権限昇格脆弱性(CVE-2025-58726、CVSS 8.8)に対処した。「Ghost SPN」と呼ばれるDNS解決できないサービス主体名とKerberosリフレクション攻撃を組み合わせること

    @nakajimeeee

    30 Oct 2025

    8916 Impressions

    30 Retweets

    111 Likes

    79 Bookmarks

    0 Replies

    1 Quote

  11. ドメイン参加環境のWindowsでSYSTEM権限を奪取される恐れがある脆弱性が発見され、Microsoftが修正を公開した。Kerberos認証を悪用する反射攻撃により、攻撃者は低権限からでも完全な管理権限を得られる可能性が

    @yousukezan

    30 Oct 2025

    8965 Impressions

    33 Retweets

    126 Likes

    80 Bookmarks

    0 Replies

    1 Quote

  12. Blog post about my recent CVE-2025-58726, aka “The Ghost Reflection” is out, read it here: https://t.co/KnuLXeNLUc 🙃

    @decoder_it

    29 Oct 2025

    9215 Impressions

    62 Retweets

    121 Likes

    60 Bookmarks

    2 Replies

    0 Quotes

  13. **CVE-2025-58726** is a security flaw identified in the Windows SMB (Server Message Block) Server component. It involves improper access control mechanisms, which can be exploited by an attacker to escalate privileges over a network. The vulnerability is classified as **HIGH

    @CveTodo

    14 Oct 2025

    16 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations