Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-33071

32
FAUCET Score

CVE-2025-33071 is a critical use-after-free vulnerability in the Windows KDC Proxy Service (KPSSVC) affecting multiple versions of Microsoft Windows Server. This flaw allows an unauthenticated attacker to achieve remote code execution over a network with high impact on confidentiality, integrity, and availability. While the CVSS score is 8.1 (High) due to high attack complexity, there is currently no public exploit code available (Metasploit, Nuclei, ExploitDB). However, the vulnerability has garnered significant community discussion and media coverage, indicating a high level of interest.

Impacted Technologies

VendorProductVersion(s)CPE
Range not provided by sourceCPE matchmatch criteria
cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*
r2CPE matchmatch criteria
cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*
< 10.0.14393.8148CPE matchmatch criteria
cpe:2.3:o:microsoft:windows_server_2016:*:*:*:*:*:*:*:*
< 10.0.17763.7434CPE matchmatch criteria
cpe:2.3:o:microsoft:windows_server_2019:*:*:*:*:*:*:*:*
< 10.0.20348.3745CPE matchmatch criteria
cpe:2.3:o:microsoft:windows_server_2022:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

8.1HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
2.2
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
16.99%
Probability of exploitation in next 30 days
EPSS Percentile
96.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.1699 is in the 83rd percentile among its peer group of 8,920 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (18)

microsoftpatch availablevia msrc
Product: Windows Server 2012 R2 (Server Core installation)Fixed in: 6.3.9600.22620
View patch
microsoftpatch availablevia msrc
Product: Windows Server 2019Fixed in: 10.0.17763.7434
View patch
microsoftpatch availablevia msrc
Product: Windows Server 2019 (Server Core installation)Fixed in: 10.0.17763.7434
View patch
microsoftpatch availablevia msrc
Product: Windows Server 2022Fixed in: 10.0.20348.3807
View patch
microsoftpatch availablevia msrc
Product: Windows Server 2022 (Server Core installation)Fixed in: 10.0.20348.3807
View patch
microsoftpatch availablevia msrc
Product: Windows Server 2022Fixed in: 10.0.20348.3745
View patch
microsoftpatch availablevia msrc
Product: Windows Server 2022 (Server Core installation)Fixed in: 10.0.20348.3745
View patch
microsoftpatch availablevia msrc
Product: Windows Server 2025 (Server Core installation)Fixed in: 10.0.26100.4349
View patch
microsoftpatch availablevia msrc
Product: Windows Server 2025Fixed in: 10.0.26100.4349
View patch
microsoftpatch availablevia msrc
Product: Windows Server 2025 (Server Core installation)Fixed in: 10.0.26100.4270
View patch
microsoftpatch availablevia msrc
Product: Windows Server 2025Fixed in: 10.0.26100.4270
View patch
microsoftpatch availablevia msrc
Product: Windows Server 2022, 23H2 Edition (Server Core installation)Fixed in: 10.0.25398.1665
View patch
microsoftpatch availablevia msrc
Product: Windows Server 2016Fixed in: 10.0.14393.8148
View patch
microsoftpatch availablevia msrc
Product: Windows Server 2016 (Server Core installation)Fixed in: 10.0.14393.8148
View patch
microsoftpatch availablevia msrc
Product: Windows Server 2012Fixed in: 6.2.9200.25522
View patch
microsoftpatch availablevia msrc
Product: Windows Server 2012 (Server Core installation)Fixed in: 6.2.9200.25522
View patch
microsoftpatch availablevia msrc
Product: Windows Server 2012 R2Fixed in: 6.3.9600.22620
View patch
microsoftvendor investigatingvia nvd_reference
View patch

Vendor Advisories (1)

microsoft2025-Jun/CVE-2025-33071Critical

Windows KDC Proxy Service (KPSSVC) Remote Code Execution Vulnerability

Jun 10, 2025

References

msrc.microsoft.com / update-guide/vulnerability/CVE-2025-33071
Vendor Advisory