Microsoft Windows NTLM Hash Disclosure Spoofing Vulnerability
Microsoft · Windows
Date added (CISA)
2025-04-17
Remediation due
2025-05-08
Known ransomware use
Not indicated
Remediation priority
P2 — past CISA due date
Description
Microsoft Windows NTLM contains an external control of file name or path vulnerability that allows an unauthorized attacker to perform spoofing over a network.