What happened
NetNTLMv2 hash capture in Windows explorer.exe via crafted ZIP file extraction.
Affected versions
Unknown product: See original advisory Fixed: See vendor advisory.
Why it matters
This source correlation may provide earlier visibility while structured CVE metadata is still being updated.
Detection & mitigation
- Review the original advisory and validate affected versions.
- Apply vendor-provided updates or mitigations when available.
Public PoC references
RepositoryAuthorFirst seenReference
Exploit-DB 52325Windows File Explorer Windows 10 Pro x64 - TAR ExtractionDaniel Miranda2025-06-13VerifiedExploit-DB 52310Windows File Explorer Windows 11 (23H2) - NTLM Hash DisclosureMohammed Idrees Banyamer2025-05-29VerifiedSploitusNetNTLMv2 hash capture in Windows explorer.exe via crafted ZIP file extraction.KitPloit2026-09-04T11:03:12CandidateFomovet/cve-2025-24071POC for CVE-2025-24071★ 0Fomovet2026-06-21Verifiedbuffertrychar/CVE-2025-24071-POC★ 0buffertrychar2026-05-20VerifiedSecurityLayer404/CVE-2025-24054-24071---Metasploit-ModuleMódulo de Metasploit para explotar CVE-2025-24054 (ex 24071). Exploit de filtración NTLM integrado en Metasploit para vectores de ataque basados en bibliotecas de Windows.★ 0SecurityLayer4042026-04-01CandidateAbdelrahman0Sayed/CVE-2025-24071This is a python PoC scripts for CVE-2025-24071 which is a vulnerability in Windows File Explorer that allows unauthorized access to sensitive information like NTLM Exposure.★ 1Abdelrahman0Sayed2025-12-16VerifiedWind010/CVE-2025-24054_PoCA proof of concept for CVE-2025-24054/CVE-2025-24071★ 0Wind0102025-11-09Verifiedhelidem/CVE-2025-24054_CVE-2025-24071-PoCProof of Concept for the NTLM Hash Leak via .library-ms CVE-2025-24054 / CVE-2025-24071★ 21helidem2025-04-22VerifiedAC8999/CVE-2025-24071Python script to execute CVE-2025-24071★ 0AC89992025-09-05Verifiedctabango/CVE-2025-24071_PoCExtraAlternativa CVE-2025-24071_PoC★ 2ctabango2025-03-19VerifiedRoyall-Researchers/CVE-2025-24071★ 0Royall-Researchers2025-07-05Verifiedf4dee-backup/CVE-2025-24071Windows File Explorer Spoofing Vulnerability - CVE-2025-24071★ 0f4dee-backup2025-05-26Verifiedkitploit.comNetNTLMv2 hash capture in Windows explorer.exe via crafted ZIP file extraction.ru2026-09-04T11:03:12CandidateSource timeline
Discovered through Exploit-DBView source ↗
Record history
Record created from the first normalized source observation.
Metadata and source references refreshed.