LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2025-24054: Microsoft Windows NTLM Hash Disclosure Spoofing Vulnerability

RBRecent Breaches Vulnerability Intelligence·Apr 17, 2025
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
May 8, 2025
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2025-24054 to its Known Exploited Vulnerabilities catalog on Apr 17, 2025, with a federal patch deadline of May 8, 2025 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Microsoft Windows NTLM contains an external control of file name or path vulnerability that allows an unauthorized attacker to perform spoofing over a network.

CVE-2025-24054 is a spoofing vulnerability in Microsoft Windows NTLM that stems from external control of a file name or path. An unauthorized attacker on the network can abuse this to perform spoofing, which in the NTLM context commonly risks disclosure of authentication material such as hashes. Because NTLM remains widely used for authentication across Windows environments, successful abuse can enable further credential-based attacks. Specifics of impact and affected builds must be confirmed against the Microsoft vendor advisory.

Defenders should treat this as a network-reachable authentication-related spoofing issue and prioritize inventory and remediation of Windows systems that still rely on NTLM.

How it works

The underlying weakness is CWE-73: external control of file name or path. In this class of flaw, an attacker supplies or influences a path or filename that the system later uses in a security-sensitive operation. For Microsoft Windows NTLM, the CISA summary states that the product contains such a vulnerability allowing an unauthorized attacker to perform spoofing over a network.

In practical terms for this vulnerability class, the attacker crafts a network interaction that causes a Windows host or client to treat an attacker-controlled path as legitimate. That interaction can trigger NTLM authentication toward a location the attacker chooses, resulting in hash disclosure or other spoofing effects. Exact trigger conditions, required user interaction, and precise protocol messages are not detailed here; teams must obtain those mechanics from the vendor advisory rather than assuming a particular exploit path.

Am I affected? How to find it in your systems

The vulnerability affects Microsoft Windows. NTLM is present by default on most Windows client and server editions and is commonly used for file shares, remote administration, legacy applications, and some authentication fallback scenarios. Cloud-hosted Windows instances and hybrid identity environments that still permit NTLM are also in scope until confirmed otherwise.

Inventory steps:

Telemetry and log signs of potential exploitation (general for this class):

How to remediate

Patch first. Apply the security update provided by Microsoft for CVE-2025-24054 according to the vendor instructions. Follow the CISA required action: apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

After patching, harden the NTLM attack surface:

If you can't patch immediately

Implement compensating controls while scheduling the vendor update:

These measures reduce exposure but do not replace the official update. Confirm any temporary workarounds against the vendor advisory before relying on them.

If your data may have been exposed

Actively exploited vulnerabilities of this type can lead to credential theft and subsequent breaches even when ransomware use is not documented for the CVE. If you observe indicators of exploitation or suspect NTLM hashes were disclosed, rotate affected credentials, review authentication logs for lateral movement, and follow your incident-response plan. You can also run a free exposure scan of your email addresses against known breach data to check whether related accounts have appeared in prior incidents.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMicrosoft · Windows
WeaknessCWE-73
Added to CISA KEVApr 17, 2025
Federal patch deadlineMay 8, 2025
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities