Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2025-24071_PoCExtra — Proof-of-concept exploit for CVE-2025-24071 that creates a .searchconnector-ms file to trigger SMB authentication when copied, enabling credential harvesting and lateral movement. | Kitploit
Tools/GitHubGitHub/ctabango/cve-2025-24071_pocextra
ReconnaissanceVulnerability AnalysisExploitationLateral MovementInformation GatheringNetwork Security
GitHubctabango/cve-2025-24071_pocextra

CVE-2025-24071_PoCExtra

Proof-of-concept exploit for CVE-2025-24071 that creates a .searchconnector-ms file to trigger SMB authentication when copied, enabling credential harvesting and lateral movement.

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
View Repository
2151 year agoNot yet reviewed

CVE-2025-24071_PoCExtra

Alternative CVE-2025-24071_PoC

Original Code https://github.com/0x6rss/CVE-2025-24071_PoC

When testing with another similar extension, I tried ".searchconnector-ms" using the same structure, but the issue with the first PoC also affected it.

python poc2.py

Enter the IP address of the shared resource: 192.168.88.33

File 'network_share.searchconnector-ms' created with IP 192.168.88.33.

and when sending, copying or storing the file, it automatically authenticates to the SMB resource.

//Vmware During testing, simply copying the file to a virtual machine triggered authentication to the SMB resource.

https://github.com/user-attachments/assets/2b71cc32-5010-4840-bf13-bd134c305d12

Download Tool