Exploitation of a vulnerability in Windows NTLM began about a week after patches were released last month, Check Point warns.
See also: Windows 11 24H2: Update triggers BSOD error

The vulnerability, known as CVE-2025-24054 (CVSS score 6.5), was patched in the March 2025 Patch Tuesday and is rated medium severity. It could lead to NTLM hash disclosure, allowing attackers to perform network spoofing attacks
According to announcement , successful exploitation of the vulnerability requires minimal user interaction – simply selecting or right-clicking on a malicious file is enough to activate it.
A week after the release of patches for the CVE-2025-24054 vulnerability, cybercriminals began exploiting it in attacks targeting government and private entities in Poland and Romania, Check Point reports.
Once the NTLM hash is revealed, an attacker could perform brute-force attacks to extract the user's password or perform relay attacks.
Depending on the privileges of the compromised account, the attacker could then move laterally within the network, escalate their privileges, and potentially compromise the entire domain.
See also: Windows Server 2025 restart error
Although Microsoft does not describe the CVE-2025-24054 vulnerability as actively exploited in its related announcement, Check Point observed about a dozen malicious campaigns exploiting it between March 19 and 25.The NTLM hashes that were extracted were collected from SMB servers in Australia, Bulgaria, the Netherlands, Russia, and Turkey.

One of the files contained in the compressed archive is related to the CVE-2024-43451, an NTLM hash disclosure bug in Windows, which was exploited as a zero-day by Russian cybercriminals. Another file points to an SMB server associated with the state-backed Russian APT group Fancy Bear, also known as APT28, Forest Blizzard, and Sofacy.
Check Point also warns that, in at least one campaign observed on March 25, the malicious .library-ms was distributed uncompressed.
On Thursday, the U.S. cybersecurity agency CISA added the vulnerability CVE-2025-24054 to its list of Known Exploitable Vulnerabilities (KEV). Under BOD 22-01, federal agencies are required to have patches in place by May 8. However, CISA is urging all agencies to prioritize addressing vulnerabilities on the KEV list.
See also: Windows Defender protection bypassed with XOR techniques
One worrying aspect is that attackers are exploiting vulnerabilities such as NTLM hash disclosure to bypass the authentication process and gain access to sensitive accounts without having to directly crack passwords. This allows them to move around the network with “legitimate” credentials, which makes them much more difficult to detect. Furthermore, the connection to state-sponsored groups such as APT28 (Fancy Bear), known for espionage operations and high-profile cyberattacks, suggests that such vulnerabilities are not only being exploited for financial motives but also for geopolitical purposes.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Source: securityweek
