vendor:
                    Windows
                by:
                    Abinesh Kamal K U
                6.1
                        CVSS
                    HIGH
                    NTLM Hash Leak
                    522
                        CWE
                    Product Name: Windows
                    Affected Version From:  Not specified
                    Affected Version To:  Not specified
                    Patch Exists: NO
                    Related CWE: CVE-2024-21320
                    CPE:  Not specified
                    Platforms Tested:  Windows
                    2025
                    CVE-2024-21320 – NTLM Hash Leak via Malicious Windows Theme
The exploit involves creating a malicious Windows theme file that contains a link to an attacker-controlled SMB server. When the victim opens this theme file, their NTLM hash is captured by the attacker. This vulnerability is identified as CVE-2024-21320.
Mitigation:
					To mitigate this vulnerability, users should be cautious while downloading and opening theme files from untrusted sources. Organizations should also implement network segmentation and monitoring to detect suspicious activities.