CVE-2025-24054MEDIUM 5.4CISA KEVEPSS p99.0%
CVE-2025-24054Microsoft Windows NTLM Hash Disclosure Spoofing Vulnerability
Microsoft / Windows
Description
Microsoft Windows NTLM contains an external control of file name or path vulnerability that allows an unauthorized attacker to perform spoofing over a network.
Scoring
| CVSS 3.1 | 5.4 (MEDIUM) |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N |
| EPSS | 58.97% probability of exploitation · percentile 99.0% · 2026-06-18T12:00:27Z |
| Published | 2025-03-11 |
| Last modified | 2026-02-13 |
CISA KEV entry
Added to KEV: 2025-04-17
Underlying weaknesses· 1
References
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-24054
- http://seclists.org/fulldisclosure/2025/Apr/28
- https://www.exploit-db.com/exploits/52478
- https://www.exploit-db.com/exploits/52480
- https://www.vicarius.io/vsociety/posts/cve-2025-24054-spoofing-vulnerability-in-windows-ntlm-by-microsoft-detection-script
- https://www.vicarius.io/vsociety/posts/cve-2025-24054-spoofing-vulnerability-in-windows-ntlm-by-microsoft-mitigation-script
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-24054
1
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | External Control of File Name or Pathcwe-73 | 0% | live |
(incoming)1
| Type | Target | Confidence | Tier |
|---|---|---|---|
| KEVEntry | Microsoft Windows NTLM Hash Disclosure Spoofing Vulnerabilitykev-cve-2025-24054 | 0% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.