CVE-2025-33073PoC(microsoft / windows_10_1507)

CRITICALCVSS 8.8 · HIGHCISA KEV

Exploitation observed; activity peaked at 3 mentions and remains active

Immediate actions

  • Patch microsoft windows_10_1507 systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Improper access control in Windows SMB allows an authorized attacker to elevate privileges over a network.

8.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2025-11-10. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-284

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • windows_10_1507
  • windows_10_1607
  • windows_10_1809
  • windows_10_21h2

Threat summary

  • Active exploitation appears in 6 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 24 mentions across 18 observed days

What's happening

  • Active exploitation reported across 6 signals
  • Exploit tool or code specified in 2 signals
  • PoC mentioned or linked in 9 signals
  • Patch or workaround mentioned in 7 signals
  • Technical details provided in 16 signals
  • Disclosure: 6 classified signals
  • Peaked 17d ago at 3 mentions (2026-03-27); latest day: 1
  • 24 total mentions across 18 days

Affected systems

Vendors
Products
windows_10_1507windows_10_1607windows_10_1809windows_10_21h2windows_10_22h2windows_11_22h2windows_11_23h2windows_11_24h2windows_server_2008windows_server_2012

2 versions affected across 15 products

Deep dive

Activity timeline24 mentions / 18d
01223Mentions · 2026-03-27: 3Mentions · 2026-03-28: 1Mentions · 2026-03-30: 2Mentions · 2026-03-31: 1Mentions · 2026-04-07: 1Mentions · 2026-04-27: 1Mentions · 2026-04-28: 1Mentions · 2026-05-03: 1Mentions · 2026-05-23: 2Mentions · 2026-05-25: 1Mentions · 2026-05-26: 1Mentions · 2026-06-06: 1Mentions · 2026-06-22: 1Mentions · 2026-07-01: 3Mentions · 2026-07-07: 1Mentions · 2026-08-23: 1Mentions · 2026-08-30: 1Mentions · 2026-09-24: 1PoC Mentioned / Linked · 2026-03-27: 2PoC Mentioned / Linked · 2026-03-30: 1PoC Mentioned / Linked · 2026-04-27: 1PoC Mentioned / Linked · 2026-05-03: 1PoC Mentioned / Linked · 2026-05-23: 1PoC Mentioned / Linked · 2026-06-06: 1PoC Mentioned / Linked · 2026-07-07: 1PoC Mentioned / Linked · 2026-09-24: 1Exploit Tool / Code · 2026-03-27: 1Exploit Tool / Code · 2026-09-24: 1Active Exploitation · 2026-03-31: 1Active Exploitation · 2026-04-07: 1Active Exploitation · 2026-04-28: 1Active Exploitation · 2026-05-23: 1Active Exploitation · 2026-05-26: 1Active Exploitation · 2026-06-22: 1Patch / Workaround · 2026-03-27: 1Patch / Workaround · 2026-04-28: 1Patch / Workaround · 2026-06-22: 1Patch / Workaround · 2026-07-01: 1Patch / Workaround · 2026-07-07: 1Patch / Workaround · 2026-08-23: 1Patch / Workaround · 2026-08-30: 1Technical Details · 2026-03-27: 3Technical Details · 2026-03-30: 2Technical Details · 2026-03-31: 1Technical Details · 2026-05-03: 1Technical Details · 2026-05-23: 1Technical Details · 2026-05-25: 1Technical Details · 2026-06-22: 1Technical Details · 2026-07-01: 2Technical Details · 2026-07-07: 1Technical Details · 2026-08-23: 1Technical Details · 2026-08-30: 1Technical Details · 2026-09-24: 103-2703-2803-3003-3104-0704-2704-2805-0305-2305-2505-2606-0606-2207-0107-0708-2308-3009-24
Signal classification7 categories
PoC
729.2%
Disclosure
625.0%
Active Exploitation
520.8%
Exploit
28.3%
Patch
28.3%
General
14.2%
Referenced assets22 URLs
Classification over time
DateTotalLabels
2026-03-273
Disclosure1Exploit1PoC1
2026-03-281
General1
2026-03-302
Disclosure1PoC1
2026-03-311
Active Exploitation1
2026-04-071
Active Exploitation1
2026-04-271
PoC1
2026-04-281
Active Exploitation1
2026-05-031
PoC1
2026-05-232
Active Exploitation1PoC1
2026-05-251
False Positive1
2026-05-261
Active Exploitation1
2026-06-061
PoC1
2026-06-221
Patch1
2026-07-013
Disclosure3
2026-07-071
PoC1
2026-08-231
Disclosure1
2026-08-301
Patch1
2026-09-241
Exploit1
Full discourse20 posts
  • Praetorian@praetorianlabs
    PoC

    🔓 CVE-2025-33073: Any domain user → SYSTEM → DC TGT → domain compromise. No admin needed. SMB signing on DCs won’t save you. https://www.praetorian.com/blog/cve-2025-33073-ntlm-reflection-one-hop/ #theguardplatform #offensivesecurity https://t.co/BogiCiKqCp

    Post summary

    Praetorian’s blog outlines CVE‑2025‑33073, enabling any domain user to become SYSTEM and compromise a domain controller without admin rights; SMB signing on DCs does not mitigate this flaw.

    153114712021.6K
    8.6K followersView on X
  • Synacktiv@Synacktiv
    PoC

    Authentication reflection attacks are still not dead! In our new blogpost series, @yaumn_ shares his journey into bypassing the mitigations of CVE-2025-33073 to pop SYSTEM shells again🚀 👇 https://www.synacktiv.com/en/publications/bypassing-windows-authentication-reflection-mitigations-for-system-shells-part-1

    Post summary

    The tweet highlights a blog post revealing a proof‑of‑concept that bypasses mitigations of CVE‑2025‑33073 to spawn SYSTEM shells, with no mention of exploitation in the wild, a patch, or detailed technical data.

    25521558315.9K
    21.0K followersView on X
  • Densel@luckyhacker43
    PoC

    Bypassing Windows authentication reflection mitigations for SYSTEM shells 👾👾 🔗 https://nvd.nist.gov/vuln/detail/CVE-2025-33073 🔗 https://www.synacktiv.com/en/publications/bypassing-windows-authentication-reflection-mitigations-for-system-shells-part-1 JOIN US LINK ON BIO https://t.co/dUd6C1oNu4

    Post summary

    The tweet promotes a Synacktiv article that demonstrates bypassing Windows authentication reflection mitigations, implying a Proof of Concept for SYSTEM shells, but it does not provide code, tool details, or evidence of active exploitation.

    0150108646.2K
    2.5K followersView on X
  • Anis Haboubi |₿|@HaboubiAnis
    Disclosure

    🚨Cyberpandemie en vue : Le retour des failles SMB, version 2026. WannaCry wormisait tout avec EternalBlue. La CVE-2025-33073 permet à n’importe quel utilisateur normal d’obtenir les droits SYSTEM sur une machine via NTLM Reflection. https://core-jmp.org/2026/03/reflecting-on-your-tier-model-cve-2025-33073-and-the-one-hop-problem/ https://t.co/IkX3Mqz43V

    Post summary

    The post announces CVE‑2025‑33073, highlighting its SMB‑based NTLM reflection flaw that grants SYSTEM rights to local users, drawing parallels to the WannaCry EternalBlue exploit.

    123174639.9K
    5.0K followersView on X
  • Mr. OS@ksg93rd
    PoC

    #Offensive_security Bypassing Windows (11 24H2/Server 2025) authentication reflection mitigations for SYSTEM shells Part 1 (CVE-2025-33073) https://www.synacktiv.com/en/publications/bypassing-windows-authentication-reflection-mitigations-for-system-shells-part-1 Part 2 (CVE-2026-26128) https://www.synacktiv.com/en/publications/bypassing-windows-authentication-reflection-mitigations-for-system-shells-part // Authentication relay (or reflection) attacks will persist as long as integrity mechanisms are not enforced by default on Windows services

    Post summary

    The tweet announces a Synacktiv publication detailing how authentication reflection mitigations can be bypassed on latest Windows releases, linking to a proof‑of‑concept that demonstrates SYSTEM shell acquisition.

    011053313.6K
    3.3K followersView on X
  • DFIR Radar@DFIR_Radar
    Disclosure

    CVE-2025-33073 resurrects NTLM reflection attacks, enabling domain compromise through unconstrained delegation hosts without admin access. Any domain user can now exploit unpatched systems to capture DC TGTs and DCSync. #DFIR_Radar https://t.co/8SVaAc9wvL

    Post summary

    CVE-2025-33073 resurfaces NTLM reflection attacks, enabling domain compromises via unconstrained delegation hosts without admin rights; the post highlights technical details but no PoC, exploit tool, or patch information.

    11071563
    1.2K followersView on X
  • Ryx@PadhiyarRushi
    Exploit

    NTLM reflection is not dead!! Unicode homoglyph + Kerberos coerce → SYSTEM. After CVE-2025-33073, the SMB-client mitigation still missed arbitrary-port SMB reuse and homoglyph names (SⓇhttp://V1.AD.LOCAL). Coerce LSASS onto a multiplexed TCP session, relay with ntlmrelayx / krbrelayx, land nt authority\system. Default-on for Server 2025. Win11 24H2 signing blocks the SMB half. Follow-on: CVE-2026-24294 https://www.synacktiv.com/en/publications/bypassing-windows-authentication-reflection-mitigations-for-system-shells-part #Cybersecurity #AI #AISecurity #MCP #Claude #GPT #Infosec #Trending #ActiveDirectory #NTLM #RedTeam #Windows

    Post summary

    The post details a method to bypass Windows authentication reflection mitigations by combining Unicode homoglyphs with Kerberos coercion, highlighting the use of ntlmrelayx and krbrelayx to achieve SYSTEM-level execution.

    10053502
    954 followersView on X
  • Blue Team News@blueteamsec1
    Patch

    Fix: CVE-2025-33073 NTLM reflection not exploitable on pre-NT10.0 systems by azoxlpf · Pull Request #1245 · Pennyw0rth/NetExec https://dlvr.it/TVFJsl #cyber #threathunting #infosec

    Post summary

    The tweet announces a pull request that fixes CVE‑2025‑33073, stating that the NTLM reflection flaw is no longer exploitable on pre‑NT10.0 systems.

    000511.9K
    57.5K followersView on X
  • iototsecnews@iototsecnews
    PoC

    Windows Server 2025 を標的とする NTLM リレー攻撃:緩和策を回避する PoC の詳細 https://iototsecnews.jp/2026/06/30/poc-released-for-ntlm-reflection-bypass-vulnerability-that-emanbles-system-access-on-windows-server/ 脆弱性 CVE-2025-33073 の修正を回避する手法について解説する記事です。原因は、Microsoft による最初の対策が特定の SMB クライアントのみに限定されていた点にあります。他のプロトコルや機能が未修正だったことで、構造的な弱点が残ってしまいました。さらに、任意のポートを指定する機能や接続を再利用する仕組みが組み合わされ、攻撃者に特権サービスへの認証を強制する隙を与えています。一つの経路を塞ぐだけでは別ルートから悪用される点が、今回の脆弱性対策における大きな課題です。ご利用のチームは、ご注意ください。 #CyberAttack #Microsoft #PoC #Vulnerability #WindowsServer

    Post summary

    A PoC for an NTLM relay attack that bypasses the CVE-2025-33073 fix on Windows Server 2025 has been released. Key technical details are provided, but no active exploitation or exploit code is disclosed.

    02011168
    500 followersView on X
  • Alexei Belous@AlexeiBelous
    PoC

    Praetorian walked through the full chain on March 27: CVE-2025-33073 gives any domain user SYSTEM on hosts without SMB signing. Add unconstrained delegation, and one hop later you have the DC's TGT from LSASS and a DCSync to krbtgt.

    Post summary

    Praetorian demonstrated how CVE‑2025‑33073 can be used to elevate domain users to SYSTEM on SMB‑unsigned hosts, then leverage unconstrained delegation for a follow‑on DCSync, but no public exploit code or live attacks were reported.

    10011197
    6 followersView on X
  • shilohme@1Loveat
    PoC

    @Defte_ @azoxlpf Thank you for the explanation. But I managed to replicate CVE-2025-33073 on Windows Server 2012 Standard, while it didn't work on the Datacenter version. I'm not sure why that is

    Post summary

    The tweet indicates that the author replicated CVE-2025-33073 on Windows Server 2012 Standard, demonstrating a working proof‑of‑concept, but provides no further exploitation, patch, or vulnerability details.

    10010691
    5 followersView on X
  • إبراهيم بوحيمد | Ibrahim Buhaimed@buhaimedi
    Disclosure

    هذه النتيجة أثبتت أن تصحيح CVE-2025-33073 عالج المسار الأول، لكنه لم يعالج أصل المشكلة بالكامل. Microsoft تعاملت مع هذا الـ bypass كثغرة مستقلة جديدة: CVE-2026-24294

    Post summary

    The statement indicates that Microsoft’s patch for CVE‑2025‑33073 did not fully address the issue, resulting in a new vulnerability (CVE‑2026‑24294). No PoC, exploit, or active attack evidence is presented.

    1000085
    49.2K followersView on X
  • إبراهيم بوحيمد | Ibrahim Buhaimed@buhaimedi
    Disclosure

    Microsoft وصفت CVE-2025-33073 كالتالي: ـWindows SMB Client Elevation of Privilege السبب: Improper Access Control الدرجة: CVSS 8.8 التصنيف: Important المهاجم لازم يكون authenticated ولا تحتاج user interaction

    Post summary

    Microsoft has disclosed technical details for CVE-2025-33073, describing it as an elevation‑of‑privilege flaw in the SMB client with a CVSS score of 8.8 that requires authentication but no user interaction.

    1000074
    49.2K followersView on X
  • إبراهيم بوحيمد | Ibrahim Buhaimed@buhaimedi
    Disclosure

    إذا نجح الـ relay، المهاجم يفتح جلسة SMB بهوية الخدمة التي أُجبرت على الاتصال. وإذا كانت هذه الخدمة تعمل كـ SYSTEM، فالنتيجة قد تكون: SYSTEM shell وهذي كانت الفكرة الأساسية لثغره CVE-2025-33073

    Post summary

    The post explains a relay‐based SMB exploitation path that could result in a SYSTEM shell for CVE‑2025‑33073 but does not provide PoC, exploit code, or patch information.

    1000088
    49.2K followersView on X
  • shilohme@1Loveat
    False Positive

    @azoxlpf @Defte_ I am very sorry for the oversight. You are indeed correct that CVE-2025-33073 cannot be successfully exploited on Microsoft Windows Server 2012 R2 Standard. Upon verification, the MsvIsIpAddressLocal function is not exported in msv1_0.dll

    Post summary

    The message clarifies that CVE-2025-33073 is not exploitable on Windows Server 2012 R2 Standard because a required function is missing.

    10000243
    5 followersView on X
  • VulnTracker@vuln_tracker
    Active Exploitation

    @Synacktiv @yaumn_ you patched CVE-2025-33073. the mitigations are in place. and somehow SYSTEM shells are still popping this is why we tracks bypasses, not just CVEs. http://vulntracker.io

    Post summary

    Despite the patch and mitigations for CVE‑2025‑33073, the tweet reports that SYSTEM shells continue to pop, indicating ongoing exploitation possibly due to bypass techniques.

    00001648
    581 followersView on X
  • DFIR Radar@DFIR_Radar
    Exploit

    Source: https://www.praetorian.com/blog/cve-2025-33073-ntlm-reflection-one-hop/

    Post summary

    Praetorian’s blog exposes CVE‑2025‑33073, an NTLM one‑hop reflection flaw, by providing PoC code, exploitation instructions, and mitigation guidance, though it notes no active exploitation yet.

    00010205
    1.0K followersView on X
  • RST Cloud@rst_cloud
    Disclosure

    #threatreport #HighCompleteness VEEAM UNDER FIRE: Understanding CVE-2026–44963 & Ransomware Group Exploit Claims | 20-08-2026 Source: https://theravenfile.com/2026/08/20/veeam-under-fire-understanding-cve-2026-44963-ransomware-group-exploit-claims/ Key details below ↓ 🧑‍💻Actors/Campaigns: Lynx_ransomware Carbanak Dragonforce Vice_society Lazarus Bluenoroff Warlock Hunters_international Teampcp 💀Threats: Lynx, Akira_ransomware, Fog_ransomware, Credential_harvesting_technique, Credential_dumping_technique, Qilin_ransomware, Rclone_tool, Conti, Blackbasta, Kerberoasting_technique, Bitsadmin_tool, Pdq_deploy_tool, Cuba_ransomware, Cobalt_strike_tool, Bughatch, Burntcigar, Metasploit_tool, Defendercontrol_tool, Veeamhax, Anydesk_tool, Simplehelp_tool, Medusa_ransomware, Clop, Lemurloot, Rhysida, Secretsdump_tool, Putty_tool, Nltest_tool, Ransomhub, Lockbit, Dcsync_technique, Gentlekiller, Av-killer, Hexkiller, Throttleblood, Havockiller, Oxideharvest, Impacket_tool, Wmiexec_tool, Netexec_tool, Inc_ransomware, Anubis, Dire_wolf, Wevtutil_tool, Shadow_copies_delete_technique, Vssadmin_tool, Everest_ransomware, Supply_chain_technique, 🎯Victims: Data backup and recovery sector 🏭Industry: Critical_infrastructure 🌐Geo: Dprk, Latin american 🔓CVEs: CVE-2023-3519 \[[Vulners](https://vulners.com/cve/CVE-2023-3519)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - citrix netscaler_application_delivery_controller (<12.1-55.297, <13.0-91.13, <13.1-37.159, <13.1-49.13) - citrix netscaler_gateway (<13.0-91.13, <13.1-49.13) CVE-2026-44963 \[[Vulners](https://vulners.com/cve/CVE-2026-44963)] - CVSS V3.1: *9.4*, - Vulners: Exploitation: True CVE-2026-12569 \[[Vulners](https://vulners.com/cve/CVE-2026-12569)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - ptc flexplm (le11.0m030, 11.1m020, 11.2.1.0, 12.0.0.0, 12.0.2.0) CVE-2023-34362 \[[Vulners](https://vulners.com/cve/CVE-2023-34362)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - progress moveit_cloud (<14.0.5.45, <14.1.6.97, <15.0.2.39) - progress moveit_transfer (<2021.0.7, <2021.1.5, <2022.0.5, <2022.1.6, <2023.0.2) CVE-2023-27532 \[[Vulners](https://vulners.com/cve/CVE-2023-27532)] - CVSS V3.1: *7.5*, - Vulners: Exploitation: True Soft: - veeam veeam_backup_\&_replication (<11.0.1.1261, 12.0.0.1420) CVE-2024-40711 \[[Vulners](https://vulners.com/cve/CVE-2024-40711)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - veeam veeam_backup_\&_replication (<12.2.0.334) CVE-2023-0669 \[[Vulners](https://vulners.com/cve/CVE-2023-0669)] - CVSS V3.1: *7.2*, - Vulners: Exploitation: True Soft: - fortra goanywhere_managed_file_transfer (<7.1.2) CVE-2025-33073 \[[Vulners](https://vulners.com/cve/CVE-2025-33073)] - CVSS V3.1: *8.8*, - Vulners: Exploitation: True Soft: - microsoft windows_10_1507 (<10.0.10240.21034) - microsoft windows_10_1607 (<10.0.14393.8148) - microsoft windows_10_1809 (<10.0.17763.7434) - microsoft windows_10_21h2 (<10.0.19044.5965) ... 📚TTPs: ⚔️Tactics: 3 🛠️Technics: 0 🤖LLM extracted TTPs:` T1068, T1078, T1210 🧨IOCs: - File: 14 - Hash: 1 💽Software: MSSQL, PostgreSQL, Hyper-V, curl, PDQ Deploy, Windows Defender, FortiGate, PsExec, MOVEit, GoAnywhere, ... 🔢Algorithms: chacha20, md5 ⚙️Win Services: SQLAgent$VEEAMSQL2008R2, VeeamTransportSvc, BackupExecJobEngine, SQLSERVERAGENT, Symantec System Recovery 📜Programming Languages: powershell #threatreport: CVE-2026-44963 is described as a critical remote code execution vulnerability affecting Veeam Backup & Replication 12.x. The flaw reportedly involves insecure deserialization and allows a low-privileged, authenticated domain user to execute arbitrary code over the network against a domain-joined Veeam backup server. Successful exploitation can result in SYSTEM-level control of the server, making the vulnerability particularly significant because backup infrastructure often provides access to sensitive data and recovery operations. The report gives the vulnerability a CVSS score of 9.4 and compares it with earlier Veeam deserialization vulnerabilities, including CVE-2024-40711. The Lynx ransomware group allegedly claimed to use a private or improved version of the vulnerability that does not require domain credentials. An underground forum advertisement similarly claimed to offer an exploit that bypasses the June 2026 patch and achieves unauthenticated SYSTEM-level remote code execution. As of mid-August 2026, these claims had not been independently verified. The report notes that there was no public technical analysis, confirmed exploitation evidence, or vendor acknowledgment demonstrating a genuine unauthenticated bypass or residual vulnerability. The claims may therefore represent negotiation tactics intended to increase ransom demands or protect an alleged exploit. The report also connects the vulnerability to a private exploit advertised in 2025, assessing that it may have been an early version of, or the same underlying issue as, CVE-2026-44963. Veeam has historically been targeted by ransomware groups, including Akira, Fog, Cuba, and FIN7, because compromising backup servers enables attackers to disrupt recovery operations before deploying ransomware. Another major Veeam attack vector is CVE-2023-27532, which can expose credentials from the Veeam backup service and database. Attackers may use these credentials for initial access or lateral movement, including through post-compromise credential-dumping activity. Regardless of whether the alleged unauthenticated exploit exists, the authenticated RCE described for CVE-2026-44963 presents a serious risk wherever domain accounts or backup infrastructure are compromised.

    Post summary

    The threat report provides technical details on Veeam’s CVE‑2026‑44963, notes a patch, and counters unverified unauthenticated exploitation claims, with no evidence of active attacks.

    00000241
    779 followersView on X
  • Silent Vector@gh0st_V3ctbrv
    Patch

    If your org runs FortiGate, Cisco ASA, or exposed RDP, you are a target. patch immediately 👇 → CVE-2024-55591 — FortiOS auth bypass → CVE-2025-32433 — Erlang/OTP SSH RCE → CVE-2025-33073 — actively exploited + disable unused RDP exposure + enforce MFA on VPN + monitor for AD Group Policy changes + segment your backups from the main network The Gentlemen don't pick soft targets; they pick unprepared ones. Don't be unprepared. 🎩 #CyberSecurity #Ransomware #TheGentlemen #ThreatIntel #InfoSec #BugBounty #BlueTeam #RaaS

    Post summary

    The post urges immediate patching of listed FortiOS and Erlang/OTP CVEs, highlights one actively exploited vulnerability, and suggests general mitigation steps.

    00000121
    9.2K followersView on X
  • ThreadLinqs@threadlinqs
    Active Exploitation

    NEW THREAT INTEL: EOL F5 + Confluence chained to NTLM relay via CVE-2025-33073 for full AD takeover. 9 detections, 31 IOCs. https://intel.threadlinqs.com/threat/TL-2026-0596 #ThreatIntel #NTLMRelay https://t.co/mFq2Idyb2z

    Post summary

    The intel confirms that CVE-2025-33073 is being actively exploited to chain an NTLM relay and fully seize Active Directory, with 9 detections and 31 IOCs reported.

    00000132
    51 followersView on X
CPE platform detail21 entries

21 of 21 entries

PartVendorProductVersionTarget SWTarget HW
OSmicrosoftwindows_10_1507--x64
OSmicrosoftwindows_10_1507--x86
OSmicrosoftwindows_10_1607--x64
OSmicrosoftwindows_10_1607--x86
OSmicrosoftwindows_10_1809--x64
OSmicrosoftwindows_10_1809--x86
OSmicrosoftwindows_10_21h2---
OSmicrosoftwindows_10_22h2---
OSmicrosoftwindows_11_22h2---
OSmicrosoftwindows_11_23h2---
OSmicrosoftwindows_11_24h2---
OSmicrosoftwindows_server_2008--x64
OSmicrosoftwindows_server_2008--x86
OSmicrosoftwindows_server_2008r2-x64
OSmicrosoftwindows_server_2012---
OSmicrosoftwindows_server_2012r2--
OSmicrosoftwindows_server_2016---
OSmicrosoftwindows_server_2019---
OSmicrosoftwindows_server_2022---
OSmicrosoftwindows_server_2022_23h2---
OSmicrosoftwindows_server_2025---

Explore more