ZeroHour

CVE-2025-21377

mass

NTLM Hash Disclosure Spoofing Vulnerability in Windows and Windows Server

CVSS 3.1
6.5 medium
EPSS
24%p98
Published
()
Modified
AI analysis

CVE-2025-21377 is an NTLM hash disclosure (spoofing) vulnerability in Microsoft Windows, tracked as CWE-73 (external control of file name or path). An attacker who can get a user to interact with attacker-influenced content, such as a crafted file or path reference, can cause Windows to authenticate or respond in a way that leaks the user's NTLM hash to an endpoint the attacker controls, consistent with the CVSS vector's network vector and required user interaction. The attacker gains the user's NTLM hash, which can be cracked offline or replayed to authenticate as (spoof) that user; the flaw affects confidentiality only, with no direct integrity or availability impact. Any user or server running the affected Windows releases is exposed, with the risk highest where users handle untrusted files or where NTLM authentication is permitted. As of the February 2025 Patch Tuesday coverage, this flaw is not reported as actively exploited and is not on the CISA KEV, with no public proof-of-concept known, though its high EPSS percentile (98th, ~24.5% chance of exploitation within 30 days) indicates elevated exploitation risk.

What to do: Apply the February 2025 (or later) Windows security updates from Windows Update or the Microsoft Update Catalog on all affected Windows 10/11 clients and Windows Server 2008/2012/2016/2019 hosts. As interim hardening, restrict outbound NTLM authentication where feasible (e.g., limiting NTLM via group policy or blocking legacy NTLM traffic), since the flaw leaks NTLM hashes that can be cracked or replayed. Because this is not yet in CISA KEV and no public PoC is known, it can be prioritized within normal patch cycles, but the high EPSS score argues for patching internet-facing and file-handling systems first.

Affected
Microsoft Windows 101507, 1607, 1809, 21H2, 22H2
Microsoft Windows 1122H2, 23H2, 24H2
Microsoft Windows Server 2008supported releases as covered by the February 2025 security updates
Microsoft Windows Server 2012supported releases as covered by the February 2025 security updates
Microsoft Windows Server 2016supported releases as covered by the February 2025 security updates
Microsoft Windows Server 2019supported releases as covered by the February 2025 security updates
Estimated exposure
mass≈1 billion+ Windows installations (affected versions span nearly the entire supported Windows client and server installed base) — The affected list covers almost all supported Windows 10/11 releases and Windows Server 2008 through 2019, and Microsoft has cited roughly 1.4 billion active Windows devices, so the plausibly affected base is on the order of a billion…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

NTLM Hash Disclosure Spoofing Vulnerability

Vendors
microsoft
Products
windows 10 1507, windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 22h2, windows 11 23h2, windows 11 24h2, windows server 2008, windows server 2012, windows server 2016, windows server 2019
Weakness
CWE-73
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

In the news