logo

A Newly Discovered Zero-Day Exposes NTLM Credentials to Theft by Lucie Cardiet

ID: 826637ef-3de2-598f-8832-b8559752da57

STIX ID: report--826637ef-3de2-598f-8832-b8559752da57

Feed Name: Vectra AI Blog

Threat Score
75/100

Date Published: 2025-01-09

Date Updated: 2026-05-01

...
...

A 0patch-disclosed zero-day in Windows enables attackers to steal NTLM hashes when a user views a malicious file in File Explorer, affecting Windows 7/Server 2008 R2 through Windows 11 24H2/Server 2022. The flaw requires minimal interaction, can expose credentials used for lateral movement and privilege escalation, and currently lacks an official Microsoft fix; the report emphasizes mitigation, detection, and Vectra AI's identity-focused defenses.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.