ZeroHour

CVE-2025-24071

PoC ×2mass

Windows File Explorer Spoofing Vulnerability Exposes Authentication Credentials

CVSS 3.1
6.5 medium
EPSS
23%p98
Published
()
Modified
AI analysis

CVE-2025-24071 is an information-exposure/spoofing flaw (CWE-200) in Windows File Explorer in which Explorer can be induced to send the user's sensitive authentication material - an NTLM credential hash, per the related Windows NTLM reporting - to an attacker-controlled resource over the network. Because the attack vector is network-based but requires user interaction (CVSS AV:N/UI:R, no privileges needed), a typical attack lures a user into viewing or opening a crafted file or remote location in File Explorer, at which point Windows automatically authenticates to the attacker's endpoint. The attacker gains high-value confidential data - the user's credential hash - which can be cracked offline or relayed to spoof/impersonate the user, with no direct integrity or availability impact. Essentially every unpatched Windows deployment is exposed: Windows 10 (1507, 1607, 1809), Windows 11 (23H2, 24H2), and Windows Server 2012 through 2025 all ship File Explorer. The flaw is not yet in CISA KEV and has one public PoC/detection reference, but the sibling Windows NTLM flaw CVE-2025-24054 has already been exploited in the wild in campaigns (including targets in Poland and Romania days after patching) attributed to EncryptHub, and this CVE's EPSS of 24.6% (98th percentile) signals elevated near-term exploitation risk.

What to do: Apply Microsoft's latest cumulative Windows security updates on all affected Windows 10, Windows 11, and Windows Server hosts - Microsoft fixed this flaw in its March 2025 Patch Tuesday releases - prioritizing servers and user-facing workstations that handle untrusted files. Until patched, block outbound SMB/NTLM to untrusted hosts (e.g., via Windows Defender Firewall) to blunt hash-leak/spoofing attempts and avoid opening or previewing untrusted files and remote locations in File Explorer. Given that the closely related NTLM flaw CVE-2025-24054 was exploited in the wild by the actor Microsoft attributes to EncryptHub soon after patching, monitor for abnormal outbound NTLM/SMB connections and treat this CVE as a likely near-term target.

Affected
microsoft Windows 101507, 1607, 1809
microsoft Windows 1123H2, 24H2
microsoft Windows Server2012, 2016, 2019, 2022, 2022 (23H2), 2025
Estimated exposure
mass~1 billion+ Windows devices (unpatched share of the ~1.4B-device global Windows install base; File Explorer is present on all listed desktop and GUI-based… — Estimate based on Windows' roughly 1.4 billion active devices and ~70% desktop OS market share, with File Explorer universal on the listed Windows 10/11 versions and on full Windows Server installations; the actually exposed population is…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an unauthorized attacker to perform spoofing over a network.

Vendors
microsoft
Products
windows 10 1507, windows 10 1607, windows 10 1809, windows 11 23h2, windows 11 24h2, windows server 2012, windows server 2016, windows server 2019, windows server 2022, windows server 2022 23h2, windows server 2025
Weakness
CWE-200
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

In the news