
CVE-2025-24071 Proof Of Concept
CVE-2025-24071 is a spoofing vulnerability in Windows File Explorer that allows an unauthenticated attacker to expose sensitive information over a network. The vulnerability arises due to the implicit trust and automatic parsing behavior of .library-ms files in Windows Explorer. By crafting malicious archive files (e.g., RAR/ZIP) containing .library-ms files with embedded SMB paths, an attacker can trigger an SMB authentication request upon extraction, potentially exposing the user's NTLM hash.
The vulnerability affects the following Windows versions:
For a comprehensive list of affected systems, refer to the Microsoft Security Update Guide.
An attacker can exploit this vulnerability by:
.library-ms file with a malicious SMB path..library-ms file within a RAR or ZIP archive..library-ms file, initiating an SMB authentication request to the attacker's server.This method leverages the behavior of Windows Explorer in handling .library-ms files and the SMB protocol's authentication mechanism.
This repository contains a PoC demonstrating the vulnerability, in this case uplaoding the file via smb:
exploit.py: Script to generate a malicious .library-ms file and package it into a ZIP archive.Usage:
python exploit.py --ip $IP --filename payload --share share-name



