CVE-2025-24054Active Exploitation(microsoft / windows_10_1507)

HIGHCVSS 5.4 · MEDIUMCISA KEV

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for microsoft windows_10_1507 systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network.

7.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2025-05-08. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-73

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • windows_10_1507
  • windows_10_1607
  • windows_10_1809
  • windows_10_21h2

Threat summary

  • Active exploitation appears in 2 classified signals
  • Public PoC and exploit tooling are both present
  • 5 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 2 signals
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Technical details provided in 4 signals
  • Peaked 4d ago at 1 mentions (2026-02-04); latest day: 1
  • 5 total mentions across 5 days

Affected systems

Vendors
Products
windows_10_1507windows_10_1607windows_10_1809windows_10_21h2windows_10_22h2windows_11_22h2windows_11_23h2windows_11_24h2windows_server_2008windows_server_2012

2 versions affected across 15 products

Deep dive

Activity timeline5 mentions / 5d
00111Mentions · 2026-02-04: 1Mentions · 2026-02-10: 1Mentions · 2026-06-05: 1Mentions · 2026-07-21: 1Mentions · 2026-08-11: 1PoC Mentioned / Linked · 2026-02-10: 1Exploit Tool / Code · 2026-02-04: 1Active Exploitation · 2026-06-05: 1Active Exploitation · 2026-08-11: 1Technical Details · 2026-02-04: 1Technical Details · 2026-02-10: 1Technical Details · 2026-07-21: 1Technical Details · 2026-08-11: 102-0402-1006-0507-2108-11
Signal classification4 categories
Active Exploitation
240.0%
Exploit
120.0%
PoC
120.0%
Disclosure
120.0%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-02-041
Exploit1
2026-02-101
PoC1
2026-06-051
Active Exploitation1
2026-07-211
Disclosure1
2026-08-111
Active Exploitation1
Full discourse5 posts
  • Red Secure Tech Ltd.@redsecuretech
    PoC

    CVE-2025-24054 PoC generates .library-ms files that trigger NTLM hash disclosure when opened in Windows Explorer. https://redsecuretech.co.uk/blog/post/windows-ntlm-hash-leak-via-library-ms-spoofing/903 #Cybersecurity #CVE202524054 #NTLM #WindowsSecurity #HashDisclosure #RedTeam #ExploitPoC #ThreatIntel #PrivilegeEscalation #RelayAttack https://t.co/XR6a9Gsd3d

    Post summary

    A PoC demonstrates that opening .library-ms files can leak NTLM hashes via CVE-2025-24054.

    0101285
    41 followersView on X
  • Cyber Research@Cyb3rR3s34rch
    Active Exploitation

    CVE-2025-24054 is a Windows NTLM spoofing flaw under active attack and showed up in an exposed attacker WebDAV malware-delivery lab. https://cyberresearch.us/li

    Post summary

    CVE-2025-24054 is an NTLM spoofing vulnerability being actively exploited, evident from its appearance in an attacker-controlled WebDAV lab.

    0000043
    69 followersView on X
  • PCMedicalist@PCMedicalist
    Disclosure

    🟦 PCMedicalist Signal · Jul 21 CVE-2025-24054 is now in CISA KEV — Beyond the Model: Harnessing Frontier AI for Stronger Cyber Defense, a privileged function with no auth in front of it. We've built agent systems and on-chain infrastructure on Blue-Team discipline for 17 years. Whether it's a PCMedicalist dApp on Base or the MCINTOSHI stack consolidating into the same infrastructure, the boundary is drawn before the first endpoint exists — not discovered after a KEV drop. "Internal" was never a control. It's a habit. We break it at the architecture layer. — PCMedicalist #CyberSecurity #InfoSec #ThreatIntel

    Post summary

    The post announces CVE‑2025‑24054 as a CISA KEV, noting it is a privileged function lacking authentication, but provides no PoC, exploit code, or patch information.

    0000054
    119 followersView on X
  • GoCocoaAI@GoCocoaAI
    Active Exploitation

    Sources: @TheHackersNews (3h ago) — https://x.com/TheHackersNews/status/2062662429297836347 | NVD — CVE-2026-32202 — https://nvd.nist.gov/vuln/detail/CVE-2026-32202 | Check Point Research — CVE-2025-24054 in the wild — https://research.checkpoint.com/2025/cve-2025-24054-ntlm-exploit-in-the-wild/ https://t.co/pWMic2C4kc

    Post summary

    The tweet points to a Check Point article claiming active exploitation of CVE-2025-24054, while also linking to the CVE entry on NVD; no PoC, patch, or technical details are provided.

    0000066
    19 followersView on X
  • 0day Signal@0dayPublishing
    Exploit

    ⚡ CVE-2025-24054: NTLM Hash Disclosure Spoofing Vu... Path traversal flaw in NTLM enables credential harvesting via SMB/WebDAV traps—trivial to weaponize with responder and ... https://zerodaysignal.com/vulnerability/CVE-2025-24054 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The post announces CVE-2025-24054, a path traversal flaw in NTLM that can be exploited to harvest credentials via SMB/WebDAV traps, and notes it can be weaponized with the responder tool.

    0000069
    132 followersView on X
CPE platform detail26 entries

26 of 26 entries

PartVendorProductVersionTarget SWTarget HW
OSmicrosoftwindows_10_1507--x64
OSmicrosoftwindows_10_1507--x86
OSmicrosoftwindows_10_1607--x64
OSmicrosoftwindows_10_1607--x86
OSmicrosoftwindows_10_1809--x64
OSmicrosoftwindows_10_1809--x86
OSmicrosoftwindows_10_21h2--arm64
OSmicrosoftwindows_10_21h2--x64
OSmicrosoftwindows_10_21h2--x86
OSmicrosoftwindows_10_22h2--arm64
OSmicrosoftwindows_10_22h2--x64
OSmicrosoftwindows_10_22h2--x86
OSmicrosoftwindows_11_22h2--arm64
OSmicrosoftwindows_11_22h2--x64
OSmicrosoftwindows_11_23h2--arm64
OSmicrosoftwindows_11_23h2--x64
OSmicrosoftwindows_11_24h2--arm64
OSmicrosoftwindows_11_24h2--x64
OSmicrosoftwindows_server_2008r2-x64
OSmicrosoftwindows_server_2012---
OSmicrosoftwindows_server_2012r2--
OSmicrosoftwindows_server_2016---
OSmicrosoftwindows_server_2019---
OSmicrosoftwindows_server_2022---
OSmicrosoftwindows_server_2022_23h2---
OSmicrosoftwindows_server_2025---

Explore more