New Zero-Click NTLM Credential Leak Exploit Bypasses Microsoft Patch for CVE-2025-24054
ID: 90a8d97e-26fc-55d4-867d-5b2ee6fb5150
STIX ID: report--90a8d97e-26fc-55d4-867d-5b2ee6fb5150
Feed Name: GBHackers
Threat Score
Cymulate Research Labs disclosed CVE-2025-50154, a zero-click vulnerability that bypasses Microsoft’s earlier CVE-2025-24054 patch by forcing Windows Explorer to retrieve remote binaries for LNK icon extraction, leaking NTLMv2-SSP hashes and exposing systems to credential theft, privilege escalation, lateral movement, and potential remote code execution; Microsoft has acknowledged the issue and a patch is expected.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
