logo

How to Protect Your Environment From the NTLM Vulnerability

ID: 2b479078-ece3-5ac3-8f64-18e4aa43e118

STIX ID: report--2b479078-ece3-5ac3-8f64-18e4aa43e118

Feed Name: Dark Reading

Threat Score
85/100

Date Published: 2024-12-20

Date Updated: 2026-04-21

Author: Roy Akerman

...
...

A zero-day in NTLM discovered by 0patch enables attackers to exfiltrate NTLM password hashes when a user merely views a crafted file in Windows Explorer, affecting Windows 7/Server 2008 R2 through Windows 11/Server 2022; captured hashes can be used for relay, pass-the-hash, or offline cracking. The report outlines mitigations including enabling Extended Protection for Authentication (EPA), LDAP channel binding, SMB signing/encryption, Group Policy auditing/restrictions for NTLM, monitoring for legacy clients, and migrating to Kerberos plus MFA.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.