HomeSecurityPatches for Windows zero-day vulnerability affecting NTLM

Fixes for Windows zero-day vulnerability affecting NTLM

Free unofficial fixes are now available for a new Windows zero-day vulnerability that allows remote attackers to steal NTLM credentials, tricking targets into opening malicious files in Windows Explorer.

See also: Google Chrome: Fixed serious zero-day vulnerability

Windows zero-day NTLM

NTLM technology has been widely exploited in NTLM relay attacks (where attackers force vulnerable network devices to authenticate to servers controlled by them) and in pass-the-hash attacks (where vulnerabilities are exploited to steal NTLM hashes, i.e. passwords that have been encrypted).

Attackers then use the stolen hash to authenticate as the compromised user, gaining access to sensitive data and extending their reach across the network. Last year, Microsoft announced plans to retire the NTLM authentication protocol in future versions of Windows 11.

Security researchers at ACROS have discovered a new NTLM hash disclosure zero-day via SCF files in Windows, while deploying fixes for another NTLM hash vulnerability. This new zero-day vulnerability has not yet received a CVE number and affects all versions of Windows, from Windows 7 to the latest Windows 11, as well as from Server 2008 R2 to Server 2025.

See also: Microsoft fixes zero-day in Windows Kernel

ACROS Security offering free and unofficial security updates for this zero-day vulnerability through the 0Patch for all affected versions of Windows, until official fixes are released by Microsoft.

Fixes for Windows zero-day vulnerability affecting NTLM

To install the micropatch on computer , create an account and install the 0patch agent. Once launched, the agent automatically applies the micropatch without requiring a system reboot, as long as there is no custom patching policy that blocks it.

In recent months, 0patch has reported three more zero-day vulnerabilities that Microsoft has either patched or not yet addressed. These include a Windows theme bug (patched as CVE-2025-21308), a Mark of the Web in Server 2012, and an NTLM Hash disclosure vulnerability for URL files (patched as CVE-2025-21377).

0patch has also previously disclosed other vulnerabilities related to NTLM hash disclosure, such as PetitPotam, PrinterBug/SpoolSample, and DFSCoerce, which have not yet received an update.

See also: Apple patches third zero-day vulnerability this year

Zero-day vulnerabilities , such as the one affecting NTLM in Windows, refer to weaknesses or errors in software or a system that are unknown to the software's creators or those responsible for the system's security. The term "zero-day" comes from the fact that, when such a vulnerability is discovered, attackers have zero days to fix it before exploiting it. These vulnerabilities are very dangerous because they can be used by malicious users (hackers) before the software manufacturer issues a patch or update to close them. Attacks that exploit these vulnerabilities are extremely dangerous and difficult to detect.

Source: bleepingcomputer

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS