CVE ID
CVE-2024-43451
Vulnerability Name
Microsoft Windows NTLMv2 Hash Disclosure Spoofing Vulnerability
- Project: Microsoft
- Product: Windows
Date
- Date Added: 2024-11-12
- Due Date: 2024-12-03
Description
Microsoft Windows contains an NTLMv2 hash spoofing vulnerability that could result in disclosing a user's NTLMv2 hash to an attacker via a file open operation. The attacker could then leverage this hash to impersonate that user.
Known To Be Used in Ransomware Campaigns?
Unknown
Action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Additional Notes
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-43451 ; https://nvd.nist.gov/vuln/detail/CVE-2024-43451
Related Security News
- Blind Eagle Uses Proton66 Hosting for Phishing, RAT Deployment on Colombian Banks
- CVE-2025-24054 Under Active Attack—Steals NTLM Credentials on File Download
- Windows NTLM vulnerability exploited in multiple attack campaigns (CVE-2025-24054)
- Blind Eagle Hacks Colombian Institutions Using NTLM Flaw, RATs and GitHub-Based Attacks
- How a Windows zero-day was exploited in the wild for months (CVE-2024-43451)
- Russian Hackers Exploit New NTLM Flaw to Deploy RAT Malware via Phishing Emails
- Microsoft Fixes 90 New Flaws, Including Actively Exploited NTLM and Task Scheduler Bugs
Top comments (0)