CVE-2025-24054

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Mar 11, 2025
CWE ID 73

Summary

CVE-2025-24054 is a newly disclosed vulnerability affecting Windows NTLM. Hackers can exploit this external control of file name or path vulnerability to carry out spoofing attacks over a network. An unauthorized attacker can manipulate the file name or path sent to the NTLM authentication server, potentially leading to the server trusting a false identity. This can result in serious security implications, including unauthorized access to sensitive information or systems. Organizations using Windows NTLM are advised to apply the necessary patches or updates as soon as possible to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share