logo

New Zero-Click NTLM Credential Leak Exploit Bypasses Microsoft Patch for CVE-2025-24054

ID: 90a8d97e-26fc-55d4-867d-5b2ee6fb5150

STIX ID: report--90a8d97e-26fc-55d4-867d-5b2ee6fb5150

Feed Name: GBHackers

Threat Score
80/100

Date Published: 2025-08-13

Date Updated: 2026-04-22

Author: Divya

...
...

Cymulate Research Labs disclosed CVE-2025-50154, a zero-click vulnerability that bypasses Microsoft’s earlier CVE-2025-24054 patch by forcing Windows Explorer to retrieve remote binaries for LNK icon extraction, leaking NTLMv2-SSP hashes and exposing systems to credential theft, privilege escalation, lateral movement, and potential remote code execution; Microsoft has acknowledged the issue and a patch is expected.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.