LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2024-43451: Microsoft Windows NTLMv2 Hash Disclosure Spoofing Vulnerability

RBRecent Breaches Vulnerability Intelligence·Nov 12, 2024
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Dec 3, 2024
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2024-43451 to its Known Exploited Vulnerabilities catalog on Nov 12, 2024, with a federal patch deadline of Dec 3, 2024 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Microsoft Windows contains an NTLMv2 hash spoofing vulnerability that could result in disclosing a user's NTLMv2 hash to an attacker via a file open operation. The attacker could then leverage this…

CVE-2024-43451 is a spoofing vulnerability in Microsoft Windows that can disclose a user's NTLMv2 hash when a file is opened. An attacker who obtains that hash may then use it to impersonate the affected user.

This class of issue matters in Windows environments because NTLM authentication material, once captured, can support unauthorized access or further activity if the environment still relies on NTLM. Public detail is limited to the CISA description; confirm exact impact and scope against the vendor advisory.

How it works

The weakness is catalogued as CWE-73 (External Control of File Name or Path). According to the available summary, Microsoft Windows contains an NTLMv2 hash spoofing vulnerability that can result in disclosing a user's NTLMv2 hash to an attacker via a file open operation. The attacker could then leverage this hash to impersonate that user.

In practical terms for defenders, the flaw involves a path or file-related operation that triggers an NTLM authentication exchange under attacker influence, allowing the hash to leave the system. No further exploit mechanics, required conditions, or payload details are provided in the source facts; treat any additional claims as unconfirmed and verify them only against the official Microsoft advisory.

Am I affected? How to find it in your systems

The vulnerability affects Microsoft Windows. It can appear on any system that processes file open operations in a way that can initiate NTLM authentication, which is common on domain-joined workstations, servers, and file-sharing hosts.

How to remediate

Apply the mitigations or updates provided by Microsoft as the primary remediation. The CISA required action is to apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

If you can't patch immediately

Until the vendor update can be applied, reduce exposure with compensating controls appropriate to NTLM hash disclosure and path-control weaknesses.

If your data may have been exposed

Actively exploited vulnerabilities of this type can lead to credential compromise and subsequent unauthorized access. The source facts do not document known ransomware use. If you suspect NTLMv2 hashes or related credentials may have been obtained, treat the accounts as potentially compromised: reset passwords or rotate credentials, review authentication logs for misuse, and follow your incident-response process. You can also run a free exposure scan of your email addresses against known breach data to check whether related accounts appear in public breach collections.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMicrosoft · Windows
WeaknessCWE-73
Added to CISA KEVNov 12, 2024
Federal patch deadlineDec 3, 2024
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities