logo

New Windows zero-day exposes NTLM credentials, gets unofficial patch

ID: fdf2f6a7-46ed-535b-8639-28370eea1c31

STIX ID: report--fdf2f6a7-46ed-535b-8639-28370eea1c31

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2024-12-06

Date Updated: 2026-03-27

Author: Bill Toulas

...
...

A newly reported zero-day in Windows lets an attacker obtain a user's NTLM credentials simply by having the victim view a malicious file in File Explorer (no file open or click required). 0patch reported the issue to Microsoft, says it affects Windows 7 through Windows 11 24H2 and Server 2022, and is offering a free unofficial micropatch until an official fix is released; Microsoft is investigating.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.