
Proof-of-concept exploit for CVE-2025-24071 that creates a .searchconnector-ms file to trigger SMB authentication when copied, enabling credential harvesting and lateral movement.
Alternative CVE-2025-24071_PoC
Original Code https://github.com/0x6rss/CVE-2025-24071_PoC
When testing with another similar extension, I tried ".searchconnector-ms" using the same structure, but the issue with the first PoC also affected it.
python poc2.py
Enter the IP address of the shared resource: 192.168.88.33
File 'network_share.searchconnector-ms' created with IP 192.168.88.33.
and when sending, copying or storing the file, it automatically authenticates to the SMB resource.
//Vmware During testing, simply copying the file to a virtual machine triggered authentication to the SMB resource.
https://github.com/user-attachments/assets/2b71cc32-5010-4840-bf13-bd134c305d12