CVE-2025-59284General(microsoft / windows_11_22h2)

MEDIUMCVSS 5.5 · MEDIUM

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Prioritize remediation for microsoft windows_11_22h2 systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

Exposure of sensitive information to an unauthorized actor in Windows NTLM allows an unauthorized attacker to perform spoofing locally.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-200

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • windows_11_22h2
  • windows_11_23h2
  • windows_11_24h2
  • windows_11_25h2

Threat summary

  • Public PoC and exploit tooling are both present
  • 10 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 4 signals
  • PoC mentioned or linked in 5 signals
  • Technical details provided in 5 signals
  • General: 4 classified signals
  • Disclosure: 2 classified signals
  • Peaked 3d ago at 3 mentions (2026-03-17); latest day: 1
  • 10 total mentions across 5 days

Affected systems

Vendors
Products
windows_11_22h2windows_11_23h2windows_11_24h2windows_11_25h2windows_server_2025

Deep dive

Activity timeline10 mentions / 5d
01223Mentions · 2026-03-09: 1Mentions · 2026-03-17: 3Mentions · 2026-03-20: 3Mentions · 2026-03-21: 2Mentions · 2026-03-27: 1PoC Mentioned / Linked · 2026-03-17: 1PoC Mentioned / Linked · 2026-03-20: 3PoC Mentioned / Linked · 2026-03-21: 1Exploit Tool / Code · 2026-03-20: 3Exploit Tool / Code · 2026-03-21: 1Technical Details · 2026-03-17: 1Technical Details · 2026-03-20: 3Technical Details · 2026-03-21: 103-0903-1703-2003-2103-27
Signal classification4 categories
General
440.0%
PoC
330.0%
Disclosure
220.0%
Exploit
110.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-091
General1
2026-03-173
Disclosure2General1
2026-03-203
Exploit1PoC2
2026-03-212
General1PoC1
2026-03-271
General1
Full discourse10 posts
  • Gray Hats@the_yellow_fall
    Exploit

    Exploit code and details for CVE-2025-59284 are now public. Discover how a Windows libarchive flaw leaks NetNTLMv2 hashes via malicious .tar archives #CVE #WindowsSecurity #PoCExploit #CyberSecurity #InfoSec #HashLeak #Vulnerability #CyberAttack #NetNTLMv2 https://securityonline.info/poc-exploit-disclosed-windows-libarchive-hash-leak-cve-2025-59284/ https://t.co/Lg0EJIfcyk

    Post summary

    Exploit code and details for CVE‑2025‑59284 have been publicly released, exposing a Windows libarchive flaw that leaks NetNTLMv2 hashes when processing malicious .tar files.

    01002591.3K
    10.7K followersView on X
  • /r/netsec@_r_netsec
    Disclosure

    CVE-2025-59284: How reading a gnu manpage led to a Windows NetNTLM phishing exploit https://sec-fault.com/blog/cve-2025-59284/

    Post summary

    The blog post announces and explains how CVE‑2025‑59284 enables a Windows NetNTLM phishing exploit, providing technical context but no evidence of active exploitation, a patch, or debunking.

    070981.6K
    32.9K followersView on X
  • Nicolas Krassas@Dinosn
    General

    CVE-2025-59284: How reading a gnu manpage led to a Windows NetNTLM phishing exploit https://sec-fault.com/blog/cve-2025-59284/

    Post summary

    The post links to a blog describing how reading a GNU manpage led to a Windows NetNTLM phishing exploit, but does not provide specific technical details, PoC, or evidence of active exploitation or mitigation.

    0001051.4K
    153.3K followersView on X
  • moton@moton
    PoC

    PoC Exploit Publicly Disclosed: Windows 'libarchive' Flaw Leaks NetNTLMv2 Hashes - https://securityonline.info/poc-exploit-disclosed-windows-libarchive-hash-leak-cve-2025-59284/

    Post summary

    A Proof of Concept exploit for CVE‑2025‑59284, affecting Windows libarchive, has been publicly disclosed, leaking NetNTLMv2 hashes. No active exploitation or patch information is mentioned.

    01032308
    658 followersView on X
  • Security Harvester@secharvesterx
    Disclosure

    CVE-2025-59284: How reading a gnu manpage led to a Windows NetNTLM phishing exploit https://sec-fault.com/blog/cve-2025-59284/ https://t.co/nb2ybo1NCE

    Post summary

    The tweet references a blog post about CVE-2025-59284, indicating the article may detail how a GNU manpage led to a NetNTLM phishing exploit, but the tweet itself contains no explicit technical or exploit information.

    00021191
    793 followersView on X
  • Security BSidesLjubljana@BSidesLjubljana
    General

    Some of what's waiting for you 🔓 CVE-2025-59284: From a GNU manpage to a Windows exploit 💸 Building a $10 anonymous attack chain 🐍 Deep dive into the VIPERTUNNEL backdoor 🤖 AI vs. the APTs: Using LLMs to find malware #BSidesLjubljana #InfoSec #Cybersecurity https://t.co/DucN4oERjK

    Post summary

    The tweet serves as a teaser for a venue session mentioning CVE‑2025‑59284, but it does not provide any PoC, exploit, active‑use data, patch, or technical depth.

    00030126
    1.4K followersView on X
  • Angel Alejos@AlejosAngel
    General

    Descubre la vulnerabilidad CVE-2025-59284 y cómo protegerte. Más info: https://sec-fault.com/blog/cve-2025-59284/ #Ciberseguridad #Vulnerabilidad

    Post summary

    El mensaje promociona la vulnerabilidad CVE‑2025‑59284 y dirige a los lectores a un blog para más información, pero no aporta detalles técnicos, exploits, o mitigaciones concretas.

    00000128
    602 followersView on X
  • CrowdCyber 🌐@CrowdCyber_Com
    PoC

    PoC Exploit Publicly Disclosed: Windows ‘libarchive’ Flaw Leaks NetNTLMv2 Hashes https://securityonline.info/poc-exploit-disclosed-windows-libarchive-hash-leak-cve-2025-59284/

    Post summary

    The post announces a publicly disclosed proof‑of‑concept exploit for CVE‑2025‑59284, a libarchive flaw that leaks NetNTLMv2 hashes, with no indication of active exploitation or patch.

    00000171
    251 followersView on X
  • Karma-X@Karma_X_Inc
    General

    CVE-2025-59284: How reading a gnu manpage led to a Windows NetNTLM phishing exploit https://www.reddit.com/r/netsec/comments/1rwguw8/cve202559284_how_reading_a_gnu_manpage_led_to_a/

    Post summary

    The supplied text references a CVE and a Reddit link but does not offer substantive technical or operational details about the vulnerability or its mitigation.

    00000114
    70 followersView on X
  • Karma-X@Karma_X_Inc
    PoC

    PoC Exploit Publicly Disclosed: Windows ‘libarchive’ Flaw Leaks NetNTLMv2 Hashes https://securityonline.info/poc-exploit-disclosed-windows-libarchive-hash-leak-cve-2025-59284/

    Post summary

    A proof‑of‑concept exploit for Windows’ libarchive (CVE‑2025‑59284) leaking NetNTLMv2 hashes has been publicly disclosed.

    00000128
    70 followersView on X
CPE platform detail5 entries

5 of 5 entries

PartVendorProductVersionTarget SWTarget HW
OSmicrosoftwindows_11_22h2---
OSmicrosoftwindows_11_23h2---
OSmicrosoftwindows_11_24h2---
OSmicrosoftwindows_11_25h2---
OSmicrosoftwindows_server_2025---

Explore more