logo

NTLM Credential Theft in Python Windows Applications

ID: e38c8627-6f7a-53f8-96e8-db88fafd0b71

STIX ID: report--e38c8627-6f7a-53f8-96e8-db88fafd0b71

Feed Name: Security Boulevard

Threat Score
75/100

Date Published: 2024-08-23

Date Updated: 2026-04-22

Author: Naveen Sunkavally

...
...

This report discloses multiple NTLMv2 hash disclosure vulnerabilities in widely used Python frameworks (Gradio — CVE-2024-34510, Jupyter Server — CVE-2024-35178, Streamlit — CVE-2024-42474) that allow unauthenticated attackers to induce SMB callbacks from Windows hosts and capture or relay NTLMv2 hashes via crafted file paths or SSRF/XXE chaining; it includes technical root causes, exploitation scenarios (direct Internet exposure and indirect SSRF-based attacks), timelines, and recommended mitigations including patches and blocking outbound SMB.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.