CVE-2025-24054

Microsoft Windows NTLM Hash Disclosure Spoofing Vulnerability

5.4
CVSS 3.1
58.9 %
EPSS (current)
2025-04-17
KEV addition
No
Ransomware

Timeline

Publication, first public exploit and KEV addition on a day axis.

Key facts

Vendor / product: Microsoft / Windows

Published: 2025-03-11 · Due (CISA): 2025-05-08

CWE: CWE-73 · EU list: no

Exploit references (metadata only)

SourceReferenceTitleDate
exploitdb52280Microsoft - NTLM Hash Disclosure Spoofing (library-ms)2025-05-01
exploitdb52478windows 10/11 - NTLM Hash Disclosure Spoofing2026-02-04
exploitdb52480Windows 10.0.17763.7009 - spoofing vulnerability2026-02-11

References only — no downloads or instructions.

Sources