PT-2025-6320 · Microsoft · Windows

Blaz Satler

+4

·

Published

2025-02-11

·

Updated

2025-08-01

·

CVE-2025-21377

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Windows versions prior to February 2025 patchday
Description: A spoofing issue allows attackers to affect the system. This issue is related to the disclosure of NTLM hash, which can be exploited by attackers. The estimated number of potentially affected devices is not specified. The vulnerability is actively exploited and can allow remote attackers to conduct spoofing attacks and gain unauthorized access to protected information.
Recommendations: As a temporary workaround, consider restricting access to sensitive resources until a patch is available. Apply the February 2025 Windows Updates to resolve the issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-01633
CVE-2025-21377

Affected Products

Windows