What happened
Microsoft Windows NTLM contains an external control of file name or path vulnerability that allows an unauthorized attacker to perform spoofing over a network.
Affected versions
Windows: See original advisory Fixed: See vendor advisory.
Why it matters
This source correlation may provide earlier visibility while structured CVE metadata is still being updated.
Detection & mitigation
- Review the original advisory and validate affected versions.
- Apply vendor-provided updates or mitigations when available.
Public PoC references
RepositoryAuthorFirst seenReference
Exploit-DB 52280Microsoft - NTLM Hash Disclosure Spoofing (library-ms)hyp3rlinx2025-05-01VerifiedExploit-DB 52480Windows 10.0.17763.7009 - spoofing vulnerabilitybeatrizfn2026-02-11VerifiedExploit-DB 52478windows 10/11 - NTLM Hash Disclosure Spoofingbeatrizfn2026-02-04VerifiedSploitusNetNTLMv2 hash capture in Windows explorer.exe via crafted ZIP file extraction.KitPloit2026-09-04T11:03:12CandidateT0tooro/cve-2025-24054-labBlue-team lab: detecting & mitigating CVE-2025-24054 (Windows NTLM hash disclosure) with Sysmon, Wazuh SIEM, and Group Policy★ 0T0tooro2026-07-01VerifiedFomovet/cve-2025-24054POC for CVE-2025-24054★ 0Fomovet2026-06-21Verifiedsimantchaudhari/CVE-2025-24054-PoC★ 0simantchaudhari2026-05-01Verifiedkaleth4/CVE--2025-24054★ 0kaleth42026-04-03CandidateSecurityLayer404/CVE-2025-24054-24071---Metasploit-ModuleMódulo de Metasploit para explotar CVE-2025-24054 (ex 24071). Exploit de filtración NTLM integrado en Metasploit para vectores de ataque basados en bibliotecas de Windows.★ 0SecurityLayer4042026-04-01VerifiedUntouchable17/CVE-2025-24054Windows File Explorer Zero Click NTLMv2-SSP Hash Disclosure★ 2Untouchable172025-11-23VerifiedWind010/CVE-2025-24054_PoCA proof of concept for CVE-2025-24054/CVE-2025-24071★ 0Wind0102025-11-09Verifiedhelidem/CVE-2025-24054_CVE-2025-24071-PoCProof of Concept for the NTLM Hash Leak via .library-ms CVE-2025-24054 / CVE-2025-24071★ 21helidem2025-04-22Verifiedrubenformation/CVE-2025-50154POCs for CVE-2025-50154 and CVE-2025-59214, zero day vulnerabilities on windows file explorer disclosing NTLMv2-SSP without user interaction. It is a bypass for the CVE-2025-24054 Security Patch★ 55rubenformation2025-08-13Candidatemoften/CVE-2025-24054Vulnerabilidad NTLM (CVE-2025-24054) explotada para robo de hashes★ 1moften2025-05-19Verifiedkitploit.comNetNTLMv2 hash capture in Windows explorer.exe via crafted ZIP file extraction.ru2026-09-04T11:03:12CandidateSploitusZero-click NTLMv2-SSP hash disclosure in Windows File Explorer via .LNK with remote SMB target.KitPloit2026-09-02T23:38:26Candidatekitploit.comZero-click NTLMv2-SSP hash disclosure in Windows File Explorer via .LNK with remote SMB target.ru2026-09-02T23:38:26CandidateSource timeline
Discovered through CISA Known Exploited VulnerabilitiesView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Record history
Record created from the first normalized source observation.
Metadata and source references refreshed.