CVE-2025-24054, NTLM Exploit in the Wild

April 17, 2025, 4:08 p.m.

Description

A critical vulnerability, CVE-2025-24054, related to NTLM hash disclosure via spoofing, has been actively exploited since March 19, 2025. The flaw allows attackers to leak NTLM hashes or user passwords using a maliciously crafted .library-ms file, potentially compromising systems. A campaign targeting government and private institutions in Poland and Romania used malspam to distribute Dropbox links containing archives exploiting this vulnerability. The exploit can be triggered with minimal user interaction, such as right-clicking or navigating to the folder containing the malicious file. This vulnerability appears to be a variant of the previously patched CVE-2024-43451, sharing several similarities.

Date

  • Created: April 16, 2025, 10:53 p.m.
  • Published: April 16, 2025, 10:53 p.m.
  • Modified: April 17, 2025, 4:08 p.m.

Indicators

  • 194.127.179.157

Attack Patterns

Additional Informations

  • Government
  • Poland
  • Romania
  • Ukraine