CVE-2025-24054: medium-severity vulnerability in Microsoft Windows 10 Version 1507
NTLM Hash Disclosure Spoofing Vulnerability
Published · Updated
Prioritize patching. It under exploitation confirmed by CISA and has a public proof of concept.
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
An attacker can trick Windows NTLM authentication into using a file path they control, allowing them to impersonate legitimate users or systems on a network without proper authorization.
CWE-73 (external control of file name or path) in Windows NTLM enables network-based spoofing attacks where an attacker manipulates file path parameters to redirect authentication attempts. The vulnerability requires network access but no authentication pre-conditions, resulting in identity spoofing with medium severity (CVSS 6.5).
The full analysis of this CVE is available in Portuguese →
In the same product, most dangerous first.