Microsoft Windows NTLMv2 Hash Disclosure Spoofing Vulnerability
Microsoft · Windows
Date added (CISA)
2024-11-12
Remediation due
2024-12-03
Known ransomware use
Not indicated
Remediation priority
P2 — past CISA due date
Description
Microsoft Windows contains an NTLMv2 hash spoofing vulnerability that could result in disclosing a user's NTLMv2 hash to an attacker via a file open operation. The attacker could then leverage this hash to impersonate that user.