CVE-2025-24071_PoC
CVE-2025-24071: Perdita di hash NTLM tramite estrazione RAR/ZIP e file .library-ms
Windows Explorer avvia automaticamente una richiesta di autenticazione SMB quando un file .library-ms viene estratto da un archivio .rar, portando alla divulgazione dell'hash NTLM. L'utente non deve aprire o eseguire il file: è sufficiente estrarlo per innescare la perdita.
articolo del blog:
https://cti.monster/blog/2025/03/18/CVE-2025-24071.html
uso
>>python poc.py
>>enter file name: your file name
>>enter IP: attacker IP
video
https://github.com/user-attachments/assets/fa6f16da-70ce-45e5-ac55-0c92a3623cad
aggiornamento:
Aggiornamento: Microsoft ha cambiato il numero CVE. Il numero CVE precedentemente definito da Microsoft, CVE-2025-24071, è stato aggiornato a CVE-2025-24054.🤷♂️
