vendor:
Windows
by:
John Page (hyp3rlinx)
4.1
CVSS
MEDIUM
Information Disclosure
200
CWE
Product Name: Windows
Affected Version From: Unknown
Affected Version To: Unknown
Patch Exists: NO
Related CWE: CVE-2025-24054
CPE: a:microsoft:windows
Platforms Tested: Windows
2018
Microsoft NTLM Hash Disclosure Spoofing (library-ms)
The Microsoft library-ms file format was found to have an NTLM hash disclosure vulnerability, where sensitive information could be exposed. Initially considered not severe by MSRC in 2018, it was later acknowledged by Microsoft and assigned CVE-2025-24054 in 2025. This vulnerability allows remote attackers to access sensitive information.
Mitigation:
To mitigate this vulnerability, users are advised to avoid opening or interacting with untrusted library-ms files. Regularly updating systems and software can also help prevent exploitation of this issue.