Cyber Research[verified]@Cyb3rR3s34rchActive Exploitation
CVE-2025-24054 is an NTLM spoofing vulnerability being actively exploited, evident from its appearance in an attacker-controlled WebDAV lab.
PCMedicalist[verified]@PCMedicalistDisclosure
The post announces CVE‑2025‑24054 as a CISA KEV, noting it is a privileged function lacking authentication, but provides no PoC, exploit code, or patch information.
GoCocoaAI[verified]@GoCocoaAIActive Exploitation
The tweet points to a Check Point article claiming active exploitation of CVE-2025-24054, while also linking to the CVE entry on NVD; no PoC, patch, or technical details are provided.
Red Secure Tech Ltd.@redsecuretechPoC
A PoC demonstrates that opening .library-ms files can leak NTLM hashes via CVE-2025-24054.
0day Signal@0dayPublishingExploit
The post announces CVE-2025-24054, a path traversal flaw in NTLM that can be exploited to harvest credentials via SMB/WebDAV traps, and notes it can be weaponized with the responder tool.