NTLM Credential Theft in Python Windows Applications
ID: e38c8627-6f7a-53f8-96e8-db88fafd0b71
STIX ID: report--e38c8627-6f7a-53f8-96e8-db88fafd0b71
Feed Name: Security Boulevard
This report discloses multiple NTLMv2 hash disclosure vulnerabilities in widely used Python frameworks (Gradio — CVE-2024-34510, Jupyter Server — CVE-2024-35178, Streamlit — CVE-2024-42474) that allow unauthenticated attackers to induce SMB callbacks from Windows hosts and capture or relay NTLMv2 hashes via crafted file paths or SSRF/XXE chaining; it includes technical root causes, exploitation scenarios (direct Internet exposure and indirect SSRF-based attacks), timelines, and recommended mitigations including patches and blocking outbound SMB.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
