PT-2026-24288 · Microsoft · Windows
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Windows Server 2025
Description
Improper authentication in the Windows SMB Server allows an authorized attacker to elevate privileges locally. This issue involves an NTLM reflection bypass, which can be used to obtain SYSTEM privileges on the affected system.
Recommendations
Update Windows Server 2025 to the latest patched version.
Exploit
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Windows