CVE-2025-24996External Control of File Name or Path in Microsoft Windows 10 Version 1507

Severity
6.5MEDIUMNVD
EPSS
0.8%
top 26.38%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 11

Description

External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages25 packages

NVDmicrosoft/windows< 10.0.14393.7876+5
NVDmicrosoft/windows_10_1507< 10.0.10240.20947
NVDmicrosoft/windows_10_1607< 10.0.14393.7876
NVDmicrosoft/windows_10_1809< 10.0.17763.7009
NVDmicrosoft/windows_10_21h2< 10.0.19044.5608

🔴Vulnerability Details

2
GHSA
GHSA-x9f4-v83p-9c3c: External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network2025-03-11
CVEList
NTLM Hash Disclosure Spoofing Vulnerability2025-03-11

📋Vendor Advisories

1
Microsoft
NTLM Hash Disclosure Spoofing Vulnerability2025-03-11

🕵️Threat Intelligence

3
Qualys
Microsoft and Adobe Patch Tuesday, March 2025 Security Update Review2025-03-11
Qualys
Microsoft and Adobe Patch Tuesday, March 2025 Security Update Review | Qualys2025-03-11
Bleepingcomputer
Microsoft March 2025 Patch Tuesday fixes 7 zero-days, 57 flaws2025-03-11
CVE-2025-24996 — External Control of File Name or Path | cvebase