216.73.216.36

CVE-2025-24054, NTLM Exploit in the Wild

· Published 16/04/2025 22:53 · Modified 17/04/2025 16:08

Export JSON

Essential information

Published
16/04/2025 22:53
Modified
17/04/2025 16:08
Tags
2025-04-16 CVE-2025-24054 malspam ntlm spoofing
Related entities
1 observables, 1 intrusion sets (apt), 5 techniques (mitre), 4 others

Description

A critical vulnerability, , related to hash disclosure via , has been actively exploited since March 19, 2025. The flaw allows attackers to leak hashes or user passwords using a maliciously crafted .library-ms file, potentially compromising systems. A campaign targeting government and private institutions in Poland and Romania used to distribute Dropbox links containing archives exploiting this vulnerability. The exploit can be triggered with minimal user interaction, such as right-clicking or navigating to the folder containing the malicious file. This vulnerability appears to be a variant of the previously patched CVE-2024-43451, sharing several similarities.

External references