Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2025-24071_PoC — CVE-2025-24071: NTLM Hash Leak via RAR/ZIP Extraction and .library-ms File | Kitploit
Tools/GitHubGitHub/0x6rss/cve-2025-24071_poc
Password CrackingReconnaissanceVulnerability AnalysisExploitationInformation GatheringRed Teaming
GitHub0x6rss/cve-2025-24071_poc

CVE-2025-24071_PoC

CVE-2025-24071: NTLM Hash Leak via RAR/ZIP Extraction and .library-ms File

View Repository
405681 year agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2025-24071_PoC

CVE-2025-24071: NTLM Hash Leak via RAR/ZIP Extraction and .library-ms File

Windows Explorer automatically initiates an SMB authentication request when a .library-ms file is extracted from a .rar archive, leading to NTLM hash disclosure. The user does not need to open or execute the file—simply extracting it is enough to trigger the leak.

blog post:

https://cti.monster/blog/2025/03/18/CVE-2025-24071.html

usage

root@kitploit:~

>>python poc.py

>>enter file name: your file name

>>enter IP: attacker IP

video

https://github.com/user-attachments/assets/fa6f16da-70ce-45e5-ac55-0c92a3623cad

update:

Update: Microsoft has changed its CVE number. The CVE number previously defined by Microsoft, CVE-2025-24071, has been updated to CVE-2025-24054.🤷‍♂️

update

Download Tool