logo

CVE-2025-24054, NTLM Exploit in the Wild

ID: d97c3956-da70-52c1-82c3-398638482667

STIX ID: report--d97c3956-da70-52c1-82c3-398638482667

Feed Name: Check Point Research

Threat Score
80/100

Date Published: 2025-04-16

Date Updated: 2026-04-27

Author: [email protected]

...
...

This report details the active exploitation of CVE-2025-24054—an NTLM hash disclosure vulnerability triggered by crafted .library-ms (and related) files—which has been observed in malspam campaigns since March 2025 targeting government and private organizations (notably in Poland and Romania). The campaigns leak NTLMv2-SSP hashes to remote SMB servers (several IPs provided), enabling offline cracking, relays, lateral movement, and potential domain compromise; the report includes IOCs (file hashes, IP addresses, email senders) and notes similarities to prior CVE-2024-43451 activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.