ZeroHour

CVE-2025-50154

PoC ×2mass

Zero-Click Sensitive Information Exposure in Windows File Explorer

CVSS 3.1
6.5 medium
EPSS
26%p98
Published
()
Modified
AI analysis

CVE-2025-50154 is an information-disclosure flaw (CWE-200) in Windows File Explorer that, per Microsoft's August 2025 advisory, allows an unauthenticated attacker on the network to expose sensitive information and perform spoofing. Public proof-of-concept write-ups characterize it as a zero-click issue in File Explorer, meaning the flaw can be triggered when the victim merely handles or views attacker-supplied content (e.g., browsing or opening a malicious file or folder), consistent with Microsoft's CVSS vector requiring only user interaction (UI:R) with no privileges or special conditions (AV:N/AC:L/PR:N). A successful attacker gains access to sensitive authentication-related information (confidentiality impact rated High), which can then be reused to impersonate or spoof the victim in network authentication; integrity and availability are not affected (CVSS 3.1: 6.5 Medium). Everyone running the listed Windows 10 and Windows 11 client versions and Windows Server 2008, 2012, 2016, or 2019 is affected, particularly workstations and servers where users browse untrusted file locations. The flaw is not yet on CISA's KEV list, but public PoCs/detection guidance exist and EPSS estimates a 25.6% probability of exploitation within 30 days (98th percentile), indicating elevated exploitation risk.

What to do: Apply Microsoft's August 2025 security updates for all listed Windows 10, Windows 11, and Windows Server versions. As an interim mitigation, block or restrict outbound SMB authentication from user workstations (e.g., TCP 445 egress to untrusted networks) and monitor for unexpected Kerberos/NTLM authentication attempts originating from File Explorer activity. Review the referenced public detection and mitigation scripts and hunt for signs of zero-click credential exposure in user environments.

Affected
microsoft Windows 101507, 1607, 1809, 21H2, 22H2 (as listed in the advisory)
microsoft Windows 1122H2, 23H2, 24H2
microsoft Windows Server2008, 2012, 2016, 2019
Estimated exposure
mass≈1 billion+ Windows devices (essentially all deployments of the listed Windows 10/11 client and Windows Server releases) — The affected CPE list spans Microsoft's broadly deployed Windows client and server families, which collectively run on well over a billion devices worldwide, so the exposed population is effectively the entire installed Windows base…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an unauthorized attacker to perform spoofing over a network.

Vendors
microsoft
Products
windows 10 1507, windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 22h2, windows 11 23h2, windows 11 24h2, windows server 2008, windows server 2012, windows server 2016, windows server 2019
Weakness
CWE-200
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

In the news