Close Menu
World Forbes – Business, Tech, AI & Global Insights
  • Home
  • AI
  • Billionaires
  • Business
  • Cybersecurity
  • Education
    • Innovation
  • Money
  • Small Business
  • Sports
  • Trump
What's Hot

Fact-checking Trump’s claim of securing $10 trillion in investments for US | Donald Trump News

May 11, 2025

Trump fires Copyright Office director after report raises questions about AI training

May 11, 2025

Is due process different for undocumented immigrants as Trump claims? | Government News

May 11, 2025
Facebook X (Twitter) Instagram
Trending
  • Fact-checking Trump’s claim of securing $10 trillion in investments for US | Donald Trump News
  • Trump fires Copyright Office director after report raises questions about AI training
  • Is due process different for undocumented immigrants as Trump claims? | Government News
  • Microsoft and OpenAI may be renegotiating their partnership
  • What percentage of US toys and Christmas goods are imported from China? | Donald Trump News
  • Polish cyclist aiming to be 1st to reach K2 base camp starts final leg of journey – Sport
  • Amazon offers peek at new human jobs in an AI bot world
  • Lyft to roll out robotaxis in Atlanta
World Forbes – Business, Tech, AI & Global InsightsWorld Forbes – Business, Tech, AI & Global Insights
Sunday, May 11
  • Home
  • AI
  • Billionaires
  • Business
  • Cybersecurity
  • Education
    • Innovation
  • Money
  • Small Business
  • Sports
  • Trump
World Forbes – Business, Tech, AI & Global Insights
Home » Fresh Windows NTLM Vulnerability Exploited in Attacks
Cybersecurity

Fresh Windows NTLM Vulnerability Exploited in Attacks

adminBy adminApril 18, 2025No Comments3 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr WhatsApp Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email
Post Views: 29


The exploitation of a Windows NTLM vulnerability started roughly a week after patches were released last month, Check Point warns.

Tracked as CVE-2025-24054 (CVSS score of 6.5) and resolved on March 2025 Patch Tuesday, the medium-severity flaw could allow NTLM hash disclosure, enabling attackers to perform spoofing attacks over a network.

According to Microsoft’s advisory, successful exploitation of the bug requires minimal interaction from the user. Simply selecting or right-clicking a malicious file could trigger the security defect.

One week after patches were rolled out for CVE-2025-24054, threat actors started exploiting it in attacks targeting government and private institutions in Poland and Romania, Check Points says.

“This vulnerability is triggered when a user extracts a ZIP archive containing a malicious .library-ms file. This event will trigger Windows Explorer to initiate an SMB authentication request to a remote server and, as a result, it leaks the user’s NTLM hash without any user interaction,” the cybersecurity firm notes.

After exposing the NTLM hash, an attacker could perform brute-force attacks to extract the user’s password, or could mount relay attacks.

Depending on the privileges of the compromised account, the attacker could then move laterally on the network, escalate privileges, and potentially compromise the domain.

While Microsoft does not flag CVE-2025-24054 as exploited in its advisory, between March 19 and March 25, Check Point observed roughly a dozen malicious campaigns targeting it. The extracted NTLM hashes were collected on SMB servers in Australia, Bulgaria, the Netherlands, Russia, and Turkey.

Advertisement. Scroll to continue reading.

“[One] campaign appears to have occurred around March 20–21, 2025. The main targets seem to have been the Polish and Romanian governments and private institutions. The campaign targeted the victims via email phishing links, which include an archive file, downloaded from Dropbox,” Check Point explains.

One of the files inside the archive is associated with CVE-2024-43451, a Windows NTLM hash disclosure bug exploited as a zero-day by Russian threat actors, while another referenced an SMB server associated with the Russian state-sponsored APT Fancy Bear, also known as APT28, Forest Blizzard, and Sofacy.

Check Point also warns that, in at least one campaign observed on March 25, the malicious .library-ms file was distributed unzipped.

On Thursday, the US cybersecurity agency CISA added CVE-2025-24054 to its Known Exploited Vulnerabilities (KEV) list. As mandated by BOD 22-01, federal agencies should patch the flaw by May 8, but CISA urges all organizations to prioritize addressing the bugs in the KEV catalog.

Related: CISA Urges Urgent Patching for Exploited CentreStack, Windows Zero-Days

Related: Microsoft Patches 125 Windows Vulns, Including Exploited CLFS Zero-Day

Related: Newly Patched Windows Zero-Day Exploited for Two Years



Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
admin
  • Website

Related Posts

In Other News: India-Pakistan Cyberattacks, Radware Vulnerabilities, xAI Leak

May 9, 2025

Popular Scraping Tool’s NPM Package Compromised in Supply Chain Attack

May 9, 2025

160,000 Impacted by Valsoft Data Breach

May 9, 2025

Malicious NPM Packages Target Cursor AI’s macOS Users

May 9, 2025

Rising Tides: Kelley Misata on Bringing Cybersecurity to Nonprofits

May 9, 2025

SAP Zero-Day Targeted Since January, Many Sectors Impacted 

May 9, 2025
Add A Comment
Leave A Reply Cancel Reply

Don't Miss
Billionaires

Skechers’ Greenbergs Set To Pocket Up To $1.1 Billion From Sale To 3G

May 6, 2025

Skechers founders Robert Greenberg (left) and Michael Greenberg (right) started the brand more than 30…

Trump Organization Admits President Still Controls His Business

May 6, 2025

Forbes Richest Person In Every State 2025

April 30, 2025

These Billionaire Signers Of The Giving Pledge Signers On Why The Philanthropy Group Still Matters

April 29, 2025
Our Picks

Fact-checking Trump’s claim of securing $10 trillion in investments for US | Donald Trump News

May 11, 2025

Trump fires Copyright Office director after report raises questions about AI training

May 11, 2025

Is due process different for undocumented immigrants as Trump claims? | Government News

May 11, 2025

Microsoft and OpenAI may be renegotiating their partnership

May 11, 2025

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

About Us
About Us

Welcome to World-Forbes.com
At World-Forbes.com, we bring you the latest insights, trends, and analysis across various industries, empowering our readers with valuable knowledge. Our platform is dedicated to covering a wide range of topics, including sports, small business, business, technology, AI, cybersecurity, and lifestyle.

Our Picks

Trump fires Copyright Office director after report raises questions about AI training

May 11, 2025

Microsoft and OpenAI may be renegotiating their partnership

May 11, 2025

Amazon offers peek at new human jobs in an AI bot world

May 11, 2025

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

Facebook X (Twitter) Instagram Pinterest
  • Home
  • About Us
  • Advertise With Us
  • Contact Us
  • DMCA Policy
  • Privacy Policy
  • Terms & Conditions
© 2025 world-forbes. Designed by world-forbes.

Type above and press Enter to search. Press Esc to cancel.