CVE-2025-24054mediumunder attackCWE-73

CVE-2025-24054: medium-severity vulnerability in Microsoft Windows 10 Version 1507

NTLM Hash Disclosure Spoofing Vulnerability

Published · Updated

77Vexday Risk Score

Prioritize patching. It under exploitation confirmed by CISA and has a public proof of concept.

ssvc Actcvss 6.5epss 59%
from disclosure to weapon0 days
Published on NVDMar 11
1st PoCJun 4
CISA KEV+37d
exploitation probability
59%top 1% of all CVEs
observed exploitation
yesCISA + VulnCheck
26 public exploit(s)
Action required by CISAfederal deadline: 2025-05-08

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

In short

An attacker can trick Windows NTLM authentication into using a file path they control, allowing them to impersonate legitimate users or systems on a network without proper authorization.

Technical detail

CWE-73 (external control of file name or path) in Windows NTLM enables network-based spoofing attacks where an attacker manipulates file path parameters to redirect authentication attempts. The vulnerability requires network access but no authentication pre-conditions, resulting in identity spoofing with medium severity (CVSS 6.5).

Summary generated and translated by AI from the official description.

The full analysis of this CVE is available in Portuguese →

External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.