PT-2025-32777 · Microsoft · Windows File Explorer+1

Ruben Enkaoua

·

Published

2025-08-12

·

Updated

2026-02-12

·

CVE-2025-50154

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Microsoft Windows versions (affected versions not specified)
Description This issue involves a security flaw in Windows File Explorer that allows an attacker to extract NTLM hashes without user interaction, even on systems with the latest security patches applied. The vulnerability stems from insufficient protection of service data when processing NTLM hashes. An attacker can exploit this by creating a specially crafted LNK file, triggering NTLM authentication requests automatically. This enables potential offline cracking or relay attacks to gain unauthorized access. The vulnerability allows for spoofing over a network and impacts the system's security. The issue is a patch bypass, meaning existing mitigations are circumvented.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Information Disclosure

Weakness Enumeration

Related Identifiers

BDU:2025-09832
CVE-2025-50154
ZDI-25-964

Affected Products

Windows
Windows File Explorer