
Ahh, so that's how they do it 😅 ---- 📌 CVE of the Week CVE-2025-59214: Zero-Click NTLM Hash Disclosure in Windows File Explorer This flaw represents a critical bypass of previous security patches, allowing attackers to extract sensitive NTLMv2-SSP hashes with zero user interaction. Exploiting this vulnerability results in: - Automatic leakage of NTLM hashes to attacker-controlled SMB servers. - Stolen hashes that can be used in relay attacks or for offline cracking to compromise other network accounts. Recommended actions: 1. Immediately install the latest cumulative security updates for Windows 10, 11, and Windows Server (2008–2025). 2. Restrict NTLM Traffic: Use Group Policy to configure "Network security: Restrict NTLM: Outbound NTLM traffic to remote servers" to Deny all where feasible. If you cannot update, apply the following mitigation to reduce exposure, available for free: https://www.vicarius.io/vsociety/posts/cve-2025-59214-mitigation-script-windows-file-explorer-spoofing-vulnerability Let us know if you need help securing your systems or understanding these steps further!
Post summary
CVE-2025-59214 is a zero‑click NTLM hash disclosure flaw that allows attackers to automatically capture NTLMv2‑SSP hashes and potentially perform relay attacks. Immediate patching and the provided mitigation script are recommended to remediate the vulnerability.
