New Windows zero-day exposes NTLM credentials, gets unofficial patch
ID: fdf2f6a7-46ed-535b-8639-28370eea1c31
STIX ID: report--fdf2f6a7-46ed-535b-8639-28370eea1c31
Feed Name: Bleeping Computer
Threat Score
A newly reported zero-day in Windows lets an attacker obtain a user's NTLM credentials simply by having the victim view a malicious file in File Explorer (no file open or click required). 0patch reported the issue to Microsoft, says it affects Windows 7 through Windows 11 24H2 and Server 2022, and is offering a free unofficial micropatch until an official fix is released; Microsoft is investigating.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
