cbcvebase.
CVE-2025-24071
published 2025-03-11

CVE-2025-24071: Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an unauthorized attacker to perform spoofing over a network.

PriorityP180medium6.5CVSS 3.1
AVNACLPRNUIRSUCHINAN
ITWEXPLOITVulnCheck KEV
Exploited in the wild
EPSS
25.07%
97.7th percentile
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an unauthorized attacker to perform spoofing over a network.

Affected

39 ranges· showing 25
VendorProductVersion rangeFixed in
microsoftwindows_10_1507< 10.0.10240.2094710.0.10240.20947
microsoftwindows_10_1607< 10.0.14393.787610.0.14393.7876
microsoftwindows_10_1809< 10.0.17763.700910.0.17763.7009
microsoftwindows_10_version_1507>= 10.0.10240.0 < 10.0.10240.2094710.0.10240.20947
microsoftwindows_10_version_1607>= 10.0.14393.0 < 10.0.14393.787610.0.14393.7876
microsoftwindows_10_version_1809>= 10.0.17763.0 < 10.0.17763.700910.0.17763.7009
microsoftwindows_10_version_21h2>= 10.0.19044.0 < 10.0.19044.560810.0.19044.5608
microsoftwindows_10_version_22h2>= 10.0.19045.0 < 10.0.19045.560810.0.19045.5608
microsoftwindows_11_23h2< 10.0.22631.503910.0.22631.5039
microsoftwindows_11_24h2< 10.0.26100.347610.0.26100.3476
microsoftwindows_11_version_22h2>= 10.0.22621.0 < 10.0.22621.503910.0.22621.5039
microsoftwindows_11_version_22h3>= 10.0.22631.0 < 10.0.22631.503910.0.22631.5039
microsoftwindows_11_version_23h2>= 10.0.22631.0 < 10.0.22631.503910.0.22631.5039
microsoftwindows_11_version_24h2>= 10.0.26100.0 < 10.0.26100.347610.0.26100.3476
microsoftwindows_server_2012
microsoftwindows_server_2012_r2>= 6.3.9600.0 < 6.3.9600.224706.3.9600.22470
microsoftwindows_server_2016< 10.0.14393.787610.0.14393.7876
microsoftwindows_server_2016>= 10.0.14393.0 < 10.0.14393.787610.0.14393.7876
microsoftwindows_server_2019< 10.0.17763.700910.0.17763.7009
microsoftwindows_server_2019>= 10.0.17763.0 < 10.0.17763.700910.0.17763.7009
microsoftwindows_server_2022< 10.0.20348.332810.0.20348.3328
microsoftwindows_server_2022>= 10.0.20348.0 < 10.0.20348.332810.0.20348.3328
microsoftwindows_server_2022_23h2< 10.0.25398.148610.0.25398.1486
microsoftwindows_server_2025< 10.0.26100.347610.0.26100.3476
microsoftwindows_server_2025>= 10.0.26100.0 < 10.0.26100.347610.0.26100.3476

Detection & IOCsextracted from sources · hover to see the quote

ip185.227.82.72
ip159.196.128.120
ip194.127.179.157
hash9ca72d969d7c5494a30e996324c6c0fcb72ae1ae
hash84132ae00239e15b50c1a20126000eed29388100
hash76e93c97ffdb5adb509c966bca22e12c4508dcaa
hash7dd0131dd4660be562bc869675772e58a1e3ac8e
hash5e42c6d12f6b51364b6bfb170f4306c5ce608b4f
hash054784f1a398a35e0c5242cbfa164df0c277da73
hash7a43c177a582c777e258246f0ba818f9e73a69ab
filenamexd.library-ms
filenamexd.zip
filenamexd.url
filenamexd.lnk
filenamexd.website
urldocument-file.ru/files/documents/zakupki/MicrosoftWord.exe
ip45.87.246.40
path\\ATTACKER_IP\SHARE_NAME
bytes
NTLMSSP_AUTH in SMB traffic to attacker-controlled server triggered by .library-ms file extraction
  • Detect .library-ms files inside ZIP or RAR archives — this is the primary delivery vector for CVE-2025-24071/CVE-2025-24054 exploitation; extraction alone (without further user interaction) triggers an outbound SMB NTLM authentication request.
  • Alert on .library-ms files whose XML content contains a UNC path (\\<IP>\<share>) pointing to an external IP address in the <url> element — this is the malicious payload structure used in CVE-2025-24071 exploits.
  • Inspect .url files for IconFile or URL fields referencing UNC paths to external IPs (e.g., IconFile=\\159.196.128[.]120\share\pentestlab.ico), which trigger NTLM authentication on file preview/interaction (CVE-2024-43451, co-delivered with CVE-2025-24071 payloads).
  • Hunt for .lnk files with a Target Path pointing to a UNC path on an external IP (e.g., \\159.196.128.120), which also trigger NTLM authentication and are co-delivered in the same exploit archive.
  • Flag files masquerading as .xls spreadsheets that are actually .library-ms files — attackers rename .library-ms files with spreadsheet-like names to trick users in phishing campaigns.
  • Correlate NTLM authentication events (Event ID 4776 / network logon type 3) with outbound SMB to IPs in Russia, Bulgaria, Netherlands, Australia, and Turkey — these were the observed hosting locations for SMB hash-collection servers in active campaigns.
  • ·CVE-2025-24071 was initially assigned its own CVE identifier but was later consolidated under CVE-2025-24054. Detection rules and IOCs may be listed under either identifier.
  • ·The exploit requires only minimal user interaction — navigating to the folder containing the extracted .library-ms file is sufficient to trigger NTLM hash leakage, even without opening the file.
  • ·The MSRC advisory states user interaction is required (UI:R) — specifically, a user must be tricked into opening a folder containing the specially crafted file.
  • ·The exploit also works via TAR archive extraction (not only ZIP/RAR), as demonstrated by a separate proof-of-concept targeting Windows 10 Pro x64.

CVSS provenance

nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
vulncheck6.5MEDIUM
vendor_msrc6.5MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.