CVE-2025-24054
Microsoft Windows: NTLM Hash Disclosure Spoofing
As of , CVE-2025-24054 in Microsoft Windows is on CISA's list of exploited vulnerabilities: CISA listed it on . Our patch-first group: Patch this week.
- Exploited
- Yes: CISA listed it on 17 April 2025
- US federal deadline
- 8 May 202521 days after CISA listed it. US federal civilian agencies must fix it by then.
- Used in ransomware campaigns
- Not known to CISA
- EPSS score
- 0.59Higher than 99% of the CVEs EPSS scores. EPSS estimates the chance of exploitation activity in the next 30 days.
- Public exploit
- 3 Exploit-DB entries
- Fix
- Vendor advice: msrc.microsoft.comLinks below, from CISA's entry.
What CISA says to do
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CISA's required action
What the flaw is
Microsoft Windows NTLM contains an external control of file name or path vulnerability that allows an unauthorized attacker to perform spoofing over a network.
CISA's description
External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network.
The CVE record's description, from microsoft
- CVE published
- 11 March 2025
- Assigned by
- microsoft
- CVSS
- 6.5 Medium (CVSS 3.1, from the CNA)
- CWE-73
- External Control of File Name or Path
- CISA SSVC, exploitation
- active
- CISA SSVC, automatable
- no
- CISA SSVC, technical impact
- partial
Timeline
- The CVE record was published.
- CISA added it to its list of exploited vulnerabilities.
- Exploit-DB published an exploit (EDB-ID 52280).
- The US federal deadline to fix it.
- Exploit-DB published an exploit (EDB-ID 52478).
- Exploit-DB published an exploit (EDB-ID 52480).
Public exploits
Facts from Metasploit's module list and Exploit-DB's index; we never copy exploit code.
- Exploit-DB: Windows 10.0.17763.7009 - spoofing vulnerabilityEDB-ID 52480, 11 February 2026
- Exploit-DB: windows 10/11 - NTLM Hash Disclosure SpoofingEDB-ID 52478, 4 February 2026
- Exploit-DB: Microsoft - NTLM Hash Disclosure Spoofing (library-ms)EDB-ID 52280, 1 May 2025
Windows: other exploited entries
| Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|
| CVE-2025-60710Link Following | Microsoft Windows | Patch nowRansomware use, listed within a year | 0.05 | ||
| CVE-2008-4250Buffer Overflow | Microsoft Windows | Patch this weekMetasploit module; EPSS 0.99; verified Exploit-DB entry | 0.99 | ||
| CVE-2008-0015Video ActiveX Control Remote Code Execution | Microsoft Windows | Patch this weekMetasploit module; EPSS 0.77; verified Exploit-DB entry | 0.77 | ||
| CVE-2013-3918Out-of-Bounds Write | Microsoft Windows | Patch this weekMetasploit module; EPSS 0.74; verified Exploit-DB entry | 0.74 | ||
| CVE-2010-2568Remote Code Execution | Microsoft Windows | Patch this weekMetasploit module; EPSS 0.91; verified Exploit-DB entry | 0.91 | ||
| CVE-2015-0016TS WebProxy Directory Traversal | Microsoft Windows | Patch this weekMetasploit module; EPSS 0.76; verified Exploit-DB entry | 0.76 | ||
| CVE-2015-2426Adobe Type Manager Library Remote Code Execution | Microsoft Windows | Patch this weekMetasploit module; EPSS 0.87; verified Exploit-DB entry | 0.87 | ||
| CVE-2014-6332Object Linking & Embedding (OLE) Automation Array Remote Code Execution | Microsoft Windows | Patch this weekMetasploit module; EPSS 0.95; verified Exploit-DB entry | 0.95 | ||
| CVE-2017-0146SMB Remote Code Execution | Microsoft Windows | Patch this weekRansomware use; Metasploit module; EPSS 0.90; verified Exploit-DB entry | 0.90 | ||
| CVE-2014-4114Object Linking & Embedding (OLE) Remote Code Execution | Microsoft Windows | Patch this weekMetasploit module; EPSS 0.82; verified Exploit-DB entry | 0.82 |
Read further
- CVE recordcve.org
- NVD entrynvd.nist.gov
- CISA's catalogcisa.gov
- EPSS for this CVEapi.first.org