← back
CVE-2024-43451

NTLM Hash Disclosure Spoofing Vulnerability

CVSS 6.5 MEDIUMEPSS 81.8%● KEVCWE-73
In short

A vulnerability allows attackers to trick systems into revealing NTLM password hashes through spoofing attacks. These hashes could potentially be used in offline cracking attempts to compromise user accounts.

Technical detail

CWE-73 weakness enables NTLM hash disclosure via spoofing vectors where attackers manipulate authentication protocols to extract credential hashes. Exploitation requires network access and can lead to unauthorized authentication or offline hash cracking, with moderate impact on confidentiality.

Summary generated and translated by AI from the official description.
NTLM Hash Disclosure Spoofing Vulnerability
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N/E:F/RL:O/RC:C
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →