Microsoft NTLM Zero-Day to Remain Unpatched Until April
ID: 77648638-fc27-597a-b9c9-65e0166d8210
STIX ID: report--77648638-fc27-597a-b9c9-65e0166d8210
Feed Name: Dark Reading
Microsoft and ACROS Security reported a Windows NTLM credential-disclosure zero-day affecting all supported Windows Workstation and Server versions; an attacker can obtain a user's NTLM hashes by getting them to view a malicious file in Explorer. Microsoft classed the issue as "Important," plans a fix in April, and updated guidance to enable Extended Protection for Authentication (EPA) to mitigate NTLM-relay attacks, while ACROS has withheld full disclosure until a patch and suggested 0patch micropatches as an interim option.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
