Summary: A vulnerability has been identified in Microsoft Windows related to NTLM that allows external control of the file name or path and can be exploited by an unauthorized attacker to perform spoofing over the network and potentially disclose NTLM hashes during downloads or authenticated requests.
Technical description: The vulnerability allows a resource referenced by an application or browser to point to an attacker-controlled path, causing the system to attempt authentication using NTLM and send the NTLM hash to the malicious server. An adversary could capture that hash and use it in relay attacks or attempt offline cracking. Although in some cases exploitation requires user interaction such as opening a file or following a link, the impact includes possible credential disclosure and lateral escalation in corporate environments.
Affected project and product: Microsoft Windows
Dates: Date added 2025-04-17 Due date 2025-05-08
Known to be used in ransomware campaigns?: Unknown
Mitigations and recommendations: Apply the patches and mitigations provided by the vendor immediately. If no patches are available, follow the applicable BOD 22-01 guidance for cloud services or consider discontinuing use of the vulnerable product. Additionally, it is recommended to minimize NTLM usage by enabling Kerberos where possible, configure and enforce blocking of outbound NTLM authentication, enable SMB signing and Extended Protection for Authentication, block malicious domains and IP addresses at the network level, and monitor unusual authentication attempts. Conduct security assessments and phishing tests to reduce the risk of exploitation through user interaction.
Additional notes and references: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-24054 https://nvd.nist.gov/vuln/detail/CVE-2025-24054
Related news: Microsoft August 2025 Patch Tuesday Fixes Kerberos Zero Day Among 111 Total New Flaws - https://www.scyscan.com/news/microsoft-august-2025-patch-tuesday-fixes-kerberos-zero-day-among-111-total-new-flaws/ Microsoft Outlook to block more risky attachments used in attacks - https://www.scyscan.com/news/microsoft-outlook-to-block-more-risky-attachments-used-in-attacks/ CVE-2025-24054 Under Active Attacks Steals NTLM Credentials on File Download - https://www.scyscan.com/news/cve-2025-24054-under-active-attacksteals-ntlm-credentials-on-file-download/ Windows NTLM hash leak flaw exploited in phishing attacks on governments - https://www.scyscan.com/news/windows-ntlm-hash-leak-flaw-exploited-in-phishing-attacks-on-governments/
About Q2BSTUDIO: Q2BSTUDIO is a custom software and application development company specialized in artificial intelligence, cybersecurity, and AWS and Azure cloud services. We offer custom software solutions and custom applications designed to integrate artificial intelligence and AI for businesses, AI agents, and business intelligence services. Our services include security assessments, implementation of mitigations against vulnerabilities such as CVE-2025-24054, development of custom AI agents, Power BI integration for advanced reporting, and consulting on cloud and cybersecurity strategies. If you need advice to protect your infrastructure, migrate to AWS and Azure cloud services, or develop custom software that incorporates artificial intelligence and business intelligence capabilities, Q2BSTUDIO can help you design and implement secure and scalable solutions.
Keywords for positioning: custom applications custom software artificial intelligence cybersecurity aws and azure cloud services business intelligence services ai for businesses AI agents power bi





