Our takeCISA added CVE-2025-33053 to its KEV catalog: this Windows IKE Extension RCE is confirmed exploited in the wild. Patch it now.Cyber Resilience desk
Sources (2)
- bleeping · bleeping
- securityweek · securityweek
What this means for you — Security leader:Apply Microsoft's patch for CVE-2025-33063 immediately on all affected Windows servers; CISA has added it to the Known Exploited Vulnerabilities catalog.
What this means for you — Lean IT orgs:If you run Windows servers, check for and install Microsoft's update for this IKE flaw right away — attackers are already using it.
What this means for you — MSP:Confirm all managed Windows servers have the latest cumulative update that fixes CVE-2025-33063; prioritize patching as CISA lists active exploitation.
What this means for you — Researcher:Monitor for new exploitation signatures of CVE-2025-33063 in Windows IKE Extension; CISA KEV addition confirms in-the-wild use.