CVE-2025-24054 is a Windows vulnerability that leaks NTLMv2-SSP hashes via malicious .library-ms files with minimal user interaction. Despite a patch released on March 11, 2025, active exploitation began within days, targeting entities in Poland and Romania. Attackers used phishing emails and SMB connections to harvest credentials. The flaw poses serious risks for privilege escalation and lateral movement if left unpatched.
What’s new on HivePro
Get through updates and upcoming events, and more directly in your inbox