Forbes: Update Windows Now — Microsoft Confirms System Takeover Danger
Forbes included a finding from NetSPI senior security consultant, Joshua Murrell, in a story that warned Microsoft Windows users about critical security vulnerabilities that require immediate updates. Murrell identified and reported on CVE-2025-26685, a vulnerability affecting Microsoft Defender for Identity, a vulnerability that shows the real-world risks that major companies such as Microsoft face.
+ + +
Microsoft users are starting to get all too familiar with being advised to act now, as confirmation of security threat after security threat is made. A Windows secure boot bypass, and attacks exploiting vulnerabilities against Windows 10 and 11 users both require users to update now. That advice is all too clearly warranted as Microsoft has confirmed yet another Windows vulnerability that demands urgent update attention, and this one can lead to a system takeover. Here’s what you need to know about CVE-2025-33073, and what you need to do. Hint: update Windows now!
CVE-2025-26685: A Microsoft Defender Attack Vulnerability For Windows Users
Joshua Murrell, a senior security consultant at NetSPI, has confirmed that CVE-2025-26685, a spoofing vulnerability impacting Microsoft Defender for Identity, can elevate privileges for a successful attacker. It’s important to note that CVE-2025-26685 alone is not enough to undertake an attack on Windows users, but when combined with other vulnerabilities in a chained attack, it becomes part of a potent exploit weaponisation that can lead to escalated privileges in Active Directory environments. In other words, the MDI sensor vulnerability, in conjunction with other vulnerabilities such as Active Directory Certificate Services vulnerabilities or Lightweight Directory Access Protocol relays, to create a domain machine account, according to Murrell. “This is not a part of the MDI sensor vulnerability,” Murrell said, “but an opportunity to demonstrate the impact it has on the environment.”
You can read the full story here.
Explore More News
TechChannel: Why Mainframe Security Postures Vary So Widely
Why does the state of mainframe security vary so widely? NetSPI’s Phil Young reveals common gaps, from FTP and weak MFA to lax data access.
SecurityPal AI: How CISOs Can Turn Everyday Awareness into Lasting Security Mindsets
NetSPI CISO, Joe Evangelisto, shares how to build a security-first culture by aligning teams, leveraging AI wisely, and turning awareness into ownership.
Techcircle: NetSPI appoints Sridhar Jayanthi as Interim CPTO
Techcircle announced NetSPI’s recently appointed interim Chief Product and Technology Officer, Sridhar Jayanthi. Read the preview below or find the full story online.