CVE-2025-21377
massNTLM Hash Disclosure Spoofing Vulnerability in Windows and Windows Server
CVE-2025-21377 is an NTLM hash disclosure (spoofing) vulnerability in Microsoft Windows, tracked as CWE-73 (external control of file name or path). An attacker who can get a user to interact with attacker-influenced content, such as a crafted file or path reference, can cause Windows to authenticate or respond in a way that leaks the user's NTLM hash to an endpoint the attacker controls, consistent with the CVSS vector's network vector and required user interaction. The attacker gains the user's NTLM hash, which can be cracked offline or replayed to authenticate as (spoof) that user; the flaw affects confidentiality only, with no direct integrity or availability impact. Any user or server running the affected Windows releases is exposed, with the risk highest where users handle untrusted files or where NTLM authentication is permitted. As of the February 2025 Patch Tuesday coverage, this flaw is not reported as actively exploited and is not on the CISA KEV, with no public proof-of-concept known, though its high EPSS percentile (98th, ~24.5% chance of exploitation within 30 days) indicates elevated exploitation risk.
What to do: Apply the February 2025 (or later) Windows security updates from Windows Update or the Microsoft Update Catalog on all affected Windows 10/11 clients and Windows Server 2008/2012/2016/2019 hosts. As interim hardening, restrict outbound NTLM authentication where feasible (e.g., limiting NTLM via group policy or blocking legacy NTLM traffic), since the flaw leaks NTLM hashes that can be cracked or replayed. Because this is not yet in CISA KEV and no public PoC is known, it can be prioritized within normal patch cycles, but the high EPSS score argues for patching internet-facing and file-handling systems first.
| Microsoft Windows 10 | 1507, 1607, 1809, 21H2, 22H2 |
| Microsoft Windows 11 | 22H2, 23H2, 24H2 |
| Microsoft Windows Server 2008 | supported releases as covered by the February 2025 security updates |
| Microsoft Windows Server 2012 | supported releases as covered by the February 2025 security updates |
| Microsoft Windows Server 2016 | supported releases as covered by the February 2025 security updates |
| Microsoft Windows Server 2019 | supported releases as covered by the February 2025 security updates |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
NTLM Hash Disclosure Spoofing Vulnerability
- Vendors
- microsoft
- Products
- windows 10 1507, windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 22h2, windows 11 23h2, windows 11 24h2, windows server 2008, windows server 2012, windows server 2016, windows server 2019
- Weakness
- CWE-73
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N