MEDIUM
CVE-2025-24054
CVSS
5.4
KEV
Description
External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network.
Summary dbcve.org
This is a Windows NTLM vulnerability where an attacker can externally control file names or paths to perform spoofing attacks over a network. The vulnerability allows an unauthorized attacker to manipulate NTLM authentication flows through path traversal or file name injection, potentially impersonating legitimate users or services.
Mitigation
Apply Microsoft security updates for this vulnerability and implement NTLM authentication restrictions (e.g., via Group Policy or registry settings) to block or limit NTLM authentication for vulnerable services.
Weakness (CWE)
CWE-73
EPSS Score
58.91%
Probability of exploitation in next 30 days
99.1th percentile
References
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-24054
Vendor Advisory
http://seclists.org/fulldisclosure/2025/Apr/28
Mailing List
https://www.exploit-db.com/exploits/52478
Exploit, Third Party Advisory, VDB Entry
https://www.exploit-db.com/exploits/52480
Exploit, Third Party Advisory, VDB Entry
https://www.vicarius.io/vsociety/posts/cve-2025-24054-spoofing-vulnerability-in-windows-ntlm-by-microsoft-detection-script
Exploit, Third Party Advisory
https://www.vicarius.io/vsociety/posts/cve-2025-24054-spoofing-vulnerability-in-windows-ntlm-by-microsoft-mitigation-script
Mitigation, Third Party Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-24054
US Government Resource
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.