CVE-2025-24054
KEVMEDIUM 6.5EPSS 58.9%
External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network.
- CVSS v3.1
- 5.4 MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N - CVSS v3.1
- 6.5 MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N - EPSS
- 58.91% chance of exploitation in the next 30 days, 99th percentile
- CISA KEV
- added 2025-04-17
- Published
- 2025-03-11
- Updated
- 2026-02-13
Proof-of-concept exploits (17)
- https://www.vicarius.io/vsociety/posts/cve-2025-24054-spoofing-vulnerability-in-windows-n…
- 0x6rss/CVE-2025-24071_PoC408★ · 2025-03-20
- Marcejr117/CVE-2025-24071_PoC25★ · 2025-05-15
- Royall-Researchers/CVE-2025-240710★ · 2025-07-05
- S4mma3l/CVE-2025-240540★ · 2025-05-01
- basekilll/CVE-2025-24054_PoC4★ · 2025-04-18
- helidem/CVE-2025-24054_CVE-2025-24071-PoC22★ · 2025-11-05
- moften/CVE-2025-240541★ · 2025-05-19
- pswalia2u/CVE-2025-24071_POC0★ · 2025-04-21
- xigney/CVE-2025-24054_PoC4★ · 2025-04-18
- Fomovet/cve-2025-24054
- SecurityLayer404/CVE-2025-24054-24071---Metasploit-Module
- Untouchable17/CVE-2025-24054
- Wind010/CVE-2025-24054_PoC
- simantchaudhari/CVE-2025-24054-PoC
- Fomovet/cve-2025-24071
- kaleth4/CVE--2025-24054
ExploitDB entries (3)
- https://www.exploit-db.com/exploits/52480
- https://www.exploit-db.com/exploits/52478
- https://www.exploit-db.com/exploits/52280