Executive brief
Microsoft Windows NTLM contains an external control of file name or path vulnerability (CWE-73) that allows an unauthorized attacker to perform spoofing over a network. This flaw can lead to NTLM hash disclosure, and it has been reported as being exploited in the wild.
Affected products
- Microsoft Windows NTLM
- Microsoft Windows Server 2008 R2 SP1
- Microsoft Windows Server 2012
- Microsoft Windows 10 1507 up to (excluding) 10.0.10240.20947
- Microsoft Windows 10 1607 up to (excluding) 10.0.14393.7876
- Microsoft Windows 10 1809 up to (excluding) 10.0.17763.7009
Timeline
- 2025-04-17: disclosed
- 2025-04-17: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2025-04-17: advisory: Microsoft published vendor advisory
- 2025-04-18: other: Initial analysis by NIST
- 2025-05-29: other: Exploit and mitigation scripts published by Vicarius vsociety