CVE-2025-24054 - Microsoft Windows NTLM Hash Disclosure Spoofing Vulnerability
项目:Microsoft
产品:Windows
添加日期:2025-04-17到期日:2025-05-08
漏洞名称
Microsoft Windows NTLM Hash Disclosure Spoofing Vulnerability
描述
Microsoft Windows NTLM contains an external control of file name or path vulnerability that allows an unauthorized attacker to perform spoofing over a network.
已知用于勒索软件活动吗?
Unknown
采集行动
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
其他说明
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-24054
https://nvd.nist.gov/vuln/detail/CVE-2025-24054
相关新闻文章
Microsoft August 2025 Patch Tuesday Fixes Kerberos Zero-Day Among 111 Total New FlawsAugust 13, 2025
Microsoft Outlook to block more risky attachments used in attacksJune 11, 2025
CVE-2025-24054 Under Active Attack—Steals NTLM Credentials on File DownloadApril 18, 2025
Windows NTLM hash leak flaw exploited in phishing attacks on governmentsApril 18, 2025