logo

Microsoft NTLM Zero-Day to Remain Unpatched Until April

ID: 77648638-fc27-597a-b9c9-65e0166d8210

STIX ID: report--77648638-fc27-597a-b9c9-65e0166d8210

Feed Name: Dark Reading

Threat Score
55/100

Date Published: 2024-12-09

Date Updated: 2026-04-21

Author: Jai Vijayan, Contributing Writer

...
...

Microsoft and ACROS Security reported a Windows NTLM credential-disclosure zero-day affecting all supported Windows Workstation and Server versions; an attacker can obtain a user's NTLM hashes by getting them to view a malicious file in Explorer. Microsoft classed the issue as "Important," plans a fix in April, and updated guidance to enable Extended Protection for Authentication (EPA) to mitigate NTLM-relay attacks, while ACROS has withheld full disclosure until a patch and suggested 0patch micropatches as an interim option.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.