Researchers reported that CVE-2025-59214 is a zero-click Windows NTLM credential-leakage flaw that bypasses prior mitigations for CVE-2025-24054 and CVE-2025-50154. A crafted shortcut can cause Windows Explorer to automatically authenticate to an attacker-controlled UNC/SMB endpoint, disclosing an NTLMv2-SSP hash without requiring victim interaction; the issue was reportedly reproduced on a fully updated Windows Server 2022 system with KB5063880 installed.
The leak stems from inconsistent validation of shortcut fields: Explorer checks icon paths but can process a UNC target path through an alternate existence-check path that initiates NTLM authentication. Attackers could crack captured hashes offline or relay them to other services, creating paths to unauthorized access, privilege escalation, lateral movement, or remote code execution depending on the exposed account and environment. Earlier reporting documented exploitation of CVE-2025-24054 in the wild, underscoring the operational risk of NTLM coercion through malicious Windows shortcut content.

See affected versions and whether adversaries are exploiting it.
5 events from the most recent confirmed update back to the earliest known activity.
Microsoft issued a March 2025 patch intended to prevent NTLMv2-SSP hash disclosure caused by shortcut-file creation in explorer.exe.
Researchers reproduced CVE-2025-59214 on a fully updated Windows Server 2022 system with KB5063880. Uploading a crafted LNK file to an SMB share open in a Domain Admin session immediately caused the session's NTLMv2-SSP hash to be received by a researcher-controlled Responder listener.
Cymulate Research Labs disclosed a further bypass to Microsoft, which assigned CVE-2025-59214. The flaw can cause Explorer shortcut handling to authenticate automatically to an attacker-controlled UNC/SMB endpoint and expose an NTLMv2-SSP hash without user interaction.
A bypass of the prior mitigations was identified using an LNK file whose Target value was a UNC path while its Icon value referenced the default shell32.dll file.
Check Point Research reported that CVE-2025-24054, an NTLM-related Windows vulnerability, was being exploited in the wild.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
cymulate.com
Open sourceresearch.checkpoint.com
Open sourcemsrc.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.