⚠ Actively exploited
Added to CISA KEV on 2024-11-12. Federal agencies required to patch by 2024-12-03. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable..

CVE-2024-43451External Control of File Name or Path in Microsoft Windows 10 Version 1507

Severity
6.5MEDIUMCNA
No vector
EPSS
90.3%
top 0.40%
CISA KEV
KEV
Added 2024-11-12
Due 2024-12-03
Exploit
Exploited in wild
Active exploitation observed
Timeline
PublishedNov 12
KEV addedNov 12
KEV dueDec 3
Latest updateNov 26
CISA Required Action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Description

NTLM Hash Disclosure Spoofing Vulnerability NTLM Hash Disclosure Spoofing Vulnerability

Affected Packages16 packages

CVEListV5microsoft/windows_server_201610.0.14393.010.0.14393.7515
CVEListV5microsoft/windows_server_201910.0.17763.010.0.17763.6532
CVEListV5microsoft/windows_server_202210.0.20348.010.0.20348.2849
CVEListV5microsoft/windows_server_202510.0.26100.010.0.26100.2314
CVEListV5microsoft/windows_server_2012_r26.3.9600.06.3.9600.22267

🔴Vulnerability Details

2
CVEList
NTLM Hash Disclosure Spoofing Vulnerability2024-11-12
VulnCheck
Microsoft Windows NTLMv2 Hash Disclosure Spoofing Vulnerability2024

🔍Detection Rules

1
Suricata
ET EXPLOIT NTLM Hash Disclosure via InternetShortcut File Inbound with UNC Path Inbound (CVE-2024-43451)2025-05-13

📋Vendor Advisories

2
Microsoft
NTLM Hash Disclosure Spoofing Vulnerability2024-11-12
CISA
Microsoft Windows NTLMv2 Hash Disclosure Spoofing Vulnerability2024-11-12

🕵️Threat Intelligence

16
Securelist
Old tech, new vulnerabilities: NTLM abuse, ongoing exploitation in 20252025-11-26
Securelist
How NTLM is being abused in 2025 cyberattacks2025-11-26
Securelist
Vulnerability landscape analysis for Q4 20242025-02-26
Securelist
Exploits and vulnerabilities in Q4 20242025-02-26
Tenable
Microsoft Patch Tuesday 2024 Year in Review2024-12-10
CVE-2024-43451 — External Control of File Name or Path | cvebase