PT-2025-10806 · Microsoft · Windows Ntlm+1

·

CVE-2025-24054

·

Published

2025-03-11

·

Updated

2026-07-21

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Microsoft Windows versions prior to March 11, 2025
Description External control of file names or paths in the Windows NTLM (NT LAN Manager) protocol allows an unauthorized attacker to perform spoofing over a network. This issue, specifically affecting the File Explorer component, can lead to the disclosure of NTLM hashes. Attackers can exploit this by convincing a user to unpack a malicious archive or open malicious .library-ms files, which triggers Windows Explorer to automatically initiate an SMB authentication request to an attacker-controlled SMB server. Real-world incidents have been recorded, including global phishing campaigns and targeted attacks against government entities in Poland and Romania, potentially linked to APT28.
Recommendations Update to the security patch released on March 11, 2025. Restrict the use of NTLM. Avoid opening or unpacking unknown files from untrusted sources.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-02760
CVE-2025-24054
GHSA-7QMG-GRCP-QF25

Affected Products

Windows
Windows Ntlm