CVE-2025-24054, NTLM Exploit in the Wild
ID: d97c3956-da70-52c1-82c3-398638482667
STIX ID: report--d97c3956-da70-52c1-82c3-398638482667
Feed Name: Check Point Research
This report details the active exploitation of CVE-2025-24054—an NTLM hash disclosure vulnerability triggered by crafted .library-ms (and related) files—which has been observed in malspam campaigns since March 2025 targeting government and private organizations (notably in Poland and Romania). The campaigns leak NTLMv2-SSP hashes to remote SMB servers (several IPs provided), enabling offline cracking, relays, lateral movement, and potential domain compromise; the report includes IOCs (file hashes, IP addresses, email senders) and notes similarities to prior CVE-2024-43451 activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
