CVE-2025-24071 is a Microsoft Windows File Explorer vulnerability in which sensitive information is exposed to an unauthorized actor, enabling spoofing over a network. Available reporting associates the issue with File Explorer handling of .library-ms content, where processing or interacting with such content can trigger outbound NTLM authentication and disclose NTLM credential material to an attacker-controlled remote system. The vulnerability is described as an information disclosure issue in Windows File Explorer and has also been categorized by Microsoft as a spoofing vulnerability. In practical attack chains, it is discussed as an NTLM hash leak vector that can be used to coerce or induce authentication from a victim system without requiring traditional code execution on the target.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
27 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (5 hidden).
This two-file repository contains a README and a standalone Python 3 proof-of-concept generator for CVE-2025-24071. The script uses only argparse, os, sys, and zipfile. It builds a Windows .library-ms XML document with a user-supplied UNC SMB target (`\\{ip}\{share}`), writes it temporarily, adds it to a ZIP archive, and deletes the intermediate file. It does not implement an SMB listener, capture hashes, crack credentials, or conduct relay itself; instead, it prints example use of Impacket smbserver or Responder. The intended delivery artifact is a ZIP which, after extraction and Explorer folder rendering on an affected unpatched Windows host, may coerce an outbound SMB authentication attempt and disclose a NetNTLMv2 response to the configured remote SMB endpoint.
This is a small, standalone Python 3.9+ exploit-artifact generator for CVE-2025-24071. The repository contains one executable script (coerce_library.py), a README with operational instructions, and a .gitignore excluding generated payloads, archives, captured hash material, and local evidence. The script optionally discovers the IPv4 address assigned to tun0, prompts for an attacker IP and payload filename, writes a .library-ms XML document containing a UNC path to \\<attacker-IP>\share, and packages that file in exploit.tar. The intended delivery workflow is to upload the TAR to a writable SMB share and extract it server-side so that the .library-ms exists loose on the share. A Windows user or process browsing that share with Explorer may cause Explorer to resolve the embedded UNC path and send NTLM authentication to the attacker listener. The code has no embedded C2, shell, credential dumper, SMB listener, or hash-cracking implementation; those steps are delegated in documentation to Responder and Hashcat. The payload destination is entirely operator supplied, making the script an operational coercion helper rather than a detection utility.
This repository is a small standalone exploit generator for CVE-2025-24071, a Microsoft Windows File Explorer spoofing/information exposure issue. The repo contains only two files: a README describing the vulnerability and exploitation concept, and a single C++ source file implementing the payload builder. The code is not a scanner or detector; it creates a malicious archive intended to trigger outbound SMB/UNC access from a vulnerable Windows host. The main capability is generation of a crafted .library-ms file containing an operator-supplied UNC path of the form \\<IP>\shared, then packaging that file into a ZIP archive named openme.zip. According to the embedded comments and README, the attack relies on Windows Explorer automatically parsing the extracted .library-ms file during indexing/preview/metadata handling, even if the victim does not explicitly open it. This can cause the target to contact an attacker-controlled SMB endpoint, which the operator is expected to monitor with a tool such as Responder. Repository structure is minimal and purpose-built: README.md documents the CVE and operational idea; main.cpp prompts for a filename and responder IP, writes the XML payload, zips it with libzip APIs, and deletes the temporary .library-ms file afterward. There is no exploit framework integration, no persistence, no post-exploitation logic, and no built-in listener. The exploit is therefore best characterized as an operational PoC/archive generator with a hardcoded delivery format and a simple credential-capture/spoofing objective.
This repository is a small proof-of-concept for NTLM hash leakage via malicious .library-ms files targeting Windows systems associated with CVE-2025-24054 and CVE-2025-24071. The repository contains three files: a README with usage notes and references, a Python generator script (exploit.py), and a sample malicious library file (xd.library-ms). The core exploit logic is in exploit.py. It accepts an attacker IP/hostname, optional SMB share name, and optional output filename, then generates an XML .library-ms file whose <url> field points to a UNC path of the form \\host\share. This is not a memory-corruption or code-execution exploit; instead, it is a credential-leak PoC. When a victim previews or opens the crafted file in Windows Explorer, Windows attempts to access the remote UNC path over SMB, which can trigger NTLM authentication to the attacker-controlled server and expose NTLMv2 hash material. The included xd.library-ms file is a ready-made sample pointing to \\10.10.14.22\share. This provides a concrete indicator of how the malicious file is structured. The exploit is straightforward and minimally weaponized: it only generates the lure file and relies on external infrastructure such as an SMB listener/Responder instance to capture hashes. No post-exploitation, cracking, relay, or shell payload is included. Notable repository inconsistencies: the README refers to generate_library_ms.py and Instructions_Responder.md, but the actual repository contains exploit.py and does not include the Responder instructions file. Despite that mismatch, the repository clearly functions as a valid PoC exploit generator.
This repository is a small Metasploit auxiliary module repository containing one exploit module (ntlm_hash_leak.rb) and a README. Because it is a Metasploit module, the relevant logic is concentrated in the single Ruby file. The module targets CVE-2025-24071, described as an NTLM hash leak in Windows Explorer triggered by extracting a ZIP archive containing a malicious .library-ms file. The exploit does not deliver code execution; instead, it creates a lure file that causes the victim system to authenticate over SMB to an attacker-controlled endpoint. The module registers four user-configurable options: FILENAME, ATTACKER_IP, LIBRARY_NAME, and SHARE_NAME. In run(), it builds XML for a .library-ms file whose <url> element contains a UNC path pointing to \\ATTACKER_IP\SHARE_NAME. It writes this XML to disk, packages it into a ZIP archive using Ruby's zip library, then deletes the standalone .library-ms file, leaving the ZIP as the deliverable artifact. It prints operator guidance indicating the ZIP should be hosted for the victim and that an SMB capture server should be running to collect NTLM hashes. It also records a Metasploit note tied to the attacker IP. Primary capability: generation of a malicious ZIP archive for credential leakage via outbound SMB authentication. Main target interaction: victim extracts the ZIP in Windows Explorer, which processes the embedded .library-ms file and attempts SMB access to the attacker-controlled UNC path. The repository is therefore a file-based/network-assisted credential capture exploit module rather than a scanner or detection script.
This repository is a small Metasploit auxiliary module project consisting of a license, a README, and one Ruby exploit module: ntlm_hash_leak.rb. Because it is a Metasploit module, the main analysis centers on that single Ruby file. The module uses Metasploit's FILEFORMAT mixin to generate a malicious ZIP archive rather than directly exploiting a remote service. Its purpose is to weaponize CVE-2025-24054, formerly referred to as CVE-2025-24071, by placing a crafted .library-ms file inside a ZIP. The embedded XML contains a search connector URL pointing to an attacker-controlled UNC path in the form \\ATTACKER_IP\SHARE_NAME. When a victim on Windows extracts or otherwise causes Explorer to process the .library-ms file, Windows attempts SMB authentication to that remote path, leaking the victim's NTLM hash. Core capabilities: the module registers configurable options for the output ZIP filename, attacker IP, .library-ms filename, and fake SMB share name; builds the malicious XML; inserts it into a ZIP archive; and writes the archive to Metasploit's local output directory. It does not itself capture hashes or deliver a shell. Instead, it prepares the lure file used to induce outbound SMB authentication. The README explains intended operational use with Metasploit's SMB capture module or external tools like Responder/Impacket. Repository structure is minimal and coherent: Readme.md documents the vulnerability, installation, and usage; ntlm_hash_leak.rb contains the exploit logic; LICENSE is standard MIT text. There is no detection-only behavior, no destructive logic, and no obvious signs of fakery. This is a real exploit module for file generation and credential leakage, best classified as a Metasploit weaponized auxiliary/file-format exploit with network impact via SMB authentication leakage.
Repository contains a small Java proof-of-concept for CVE-2025-24071 (described as NTLM hash leak via ZIP/RAR extraction and a .library-ms file). Structure: (1) Exploit.java is the sole code file and entry point; it prompts for a base filename and an attacker IP, generates an XML .library-ms file whose <url> points to a UNC share \\<ip>\shared, then packages that file into exploit.zip and deletes the temporary .library-ms from disk. (2) README.md explains the intended attack flow: attacker generates exploit.zip and runs an NTLM capture tool (Responder), victim extracts the ZIP, and the victim system attempts to access the UNC path, leaking NTLM credentials. No command execution or reverse shell is implemented; the capability is credential leakage/coercion via an outbound SMB authentication attempt.
Repository contains a Metasploit auxiliary module (CVE-2025-24071.rb) and a README. The Ruby module (Msf::Auxiliary with Msf::Exploit::FILEFORMAT) generates a malicious Windows .library-ms XML file that specifies a UNC path (\\ATTACKER_IP\SHARE_NAME) and packages it into a ZIP (FILENAME). When a victim extracts the ZIP in Windows Explorer, Explorer is expected to initiate an SMB authentication attempt to the attacker-controlled host, leaking NTLM credentials for capture/relay. The module’s core actions are: write .library-ms to disk, create ZIP via RubyZip, delete the temporary .library-ms, and report a note in Metasploit. No RCE is performed; the primary capability is NTLM hash leakage via coerced outbound SMB authentication. README provides installation and usage and suggests using Metasploit’s auxiliary/server/capture/smb to collect hashes.
This repository contains a Metasploit auxiliary module (CVE-2025-24071.rb) that exploits CVE-2025-24071, a vulnerability in Microsoft Windows Explorer. The exploit works by generating a ZIP archive containing a specially crafted .library-ms file. When a victim extracts this ZIP file using Windows Explorer, the .library-ms file causes the system to initiate an SMB authentication request to an attacker-controlled server, leaking the victim's NTLM hash. The attacker must specify their own IP address and have an SMB capture server running to collect the hashes. The repository consists of the exploit module and a README.md file with detailed usage instructions. The main attack vector is network-based, leveraging SMB protocol. The exploit is operational and integrates with Metasploit's SMB capture functionality for credential harvesting.
This repository contains a single Python exploit script (Fsociety-CVE-2025-24071.py), a README.md, and a LICENSE file. The exploit targets CVE-2025-24071, a vulnerability in Microsoft Windows where .library-ms files can be crafted to force a Windows system to authenticate to an attacker-controlled SMB server via a UNC path. The script generates a malicious .library-ms XML file embedded in a ZIP archive. When a victim extracts or views the archive, Windows Explorer automatically processes the file, causing the system to attempt authentication to the specified UNC path (e.g., \\attacker_ip\share), leaking the victim's NTLMv2 hash. The README provides detailed technical background, attack flow, and usage instructions. The exploit is operational, requiring the attacker to specify their SMB listener's IP and optionally the share name and output file name. The main attack vector is network-based, leveraging Windows' automatic processing of library files to coerce NTLM authentication. No hardcoded endpoints are present; the attacker supplies the target IP at runtime. The repository is well-documented and focused solely on this exploit.
This repository provides a proof-of-concept (PoC) exploit for CVE-2025-24054 and CVE-2025-24071, targeting a vulnerability in Windows where opening a specially crafted .library-ms file can trigger an SMB authentication attempt to an attacker-controlled server, leaking the victim's NTLM hash. The repository contains three files: a Python script (exploit.py) that generates malicious .library-ms files pointing to arbitrary UNC paths, a sample .library-ms file (xd.library-ms) configured to point to \\10.10.14.22\share, and a README with detailed usage instructions. The exploit requires the victim to open or preview the malicious file on an unpatched Windows system. The attack vector is local (user interaction required), and the main fingerprintable endpoint is the UNC path embedded in the .library-ms file. The exploit is a PoC and does not include a payload for post-exploitation, but it enables credential theft via NTLM hash capture.
This repository provides a proof-of-concept exploit for CVE-2025-24071, a Windows File Explorer spoofing vulnerability that can be abused to leak NTLM hashes. The exploit consists of a single Python script ('cve-2025-24071-exploit.py') and a README with usage instructions. The script automates the creation of a malicious .library-ms file that references an attacker-controlled SMB share, packages it into a ZIP archive, and uploads it to a writable SMB share on the target Windows system using provided credentials. When a victim opens the malicious file, their system attempts to authenticate to the attacker's SMB server, leaking NTLM hashes. The attacker is expected to run Responder or a similar tool to capture these hashes. The exploit requires the attacker to have valid SMB credentials and access to a writable share on the target. The repository is structured simply, with clear separation between documentation and exploit code, and is intended for demonstration and security testing purposes.
This repository provides a proof-of-concept exploit for CVE-2025-24071 (now CVE-2025-24054), targeting Microsoft Windows Explorer. The exploit leverages the behavior where extracting a specially crafted .library-ms file from a ZIP archive causes Windows Explorer to automatically initiate an SMB authentication request to a remote server, leaking the user's NTLM hash. The repository contains two files: a README.md with usage instructions and background, and poc.py, a Python script. The script generates a .library-ms file pointing to an attacker-specified SMB share, packages it into a ZIP file, and cleans up the temporary file. The attacker then delivers the ZIP to a victim, who, upon extraction, will leak their NTLM hash to the attacker's SMB server. The exploit does not require the victim to open or execute the file—extraction alone is sufficient. The main fingerprintable endpoints are the .library-ms file, the ZIP archive, and the SMB path (\\attacker_ip\shared).
This repository is a proof-of-concept (POC) exploit for CVE-2025-24071, an information disclosure vulnerability affecting Microsoft Windows 10 and 11 (all versions, especially 11 23H2). The exploit leverages the behavior of Windows Explorer, which automatically initiates an SMB authentication request when a specially crafted .library-ms file is extracted from a ZIP archive. The provided Python script generates such a .library-ms file, embedding an attacker-supplied SMB server IP, and packages it into a ZIP archive. When a victim extracts this ZIP on a vulnerable Windows system, their NTLM hash is leaked to the attacker's SMB server without further user interaction. The repository includes a README with setup instructions for the attacker (using Responder to capture hashes), usage steps for the exploit script, and guidance on cracking the captured NTLM hash with hashcat. The exploit is classified as a POC, as it demonstrates the vulnerability and provides the means to capture NTLM hashes, but does not automate post-exploitation steps. The main fingerprintable endpoints are the malicious .library-ms file, the ZIP archive, and the SMB path (\\<attacker_ip>\shared) used for the hash leak.
This repository provides a proof-of-concept (PoC) exploit for CVE-2025-24071, a spoofing vulnerability in Windows File Explorer. The exploit consists of a Python script (exploit.py) that generates a specially crafted .library-ms file referencing an attacker-controlled SMB share (\\<attacker-ip>\shared). The script then packages this file into a ZIP archive (exploit.zip). When a victim extracts and opens the .library-ms file on a vulnerable Windows system, Windows Explorer attempts to access the specified SMB share, causing the system to send NTLM authentication data to the attacker's server. The repository includes a README.md with detailed vulnerability information, affected versions, and mitigation steps. The exploit does not provide a full attack chain (e.g., SMB server or hash capture), but demonstrates the vulnerability trigger. The code is standalone, requires Python and the colorama library, and is operational as a PoC for security testing and awareness.
This repository is a proof-of-concept (PoC) exploit for CVE-2025-24071, a vulnerability in Microsoft Windows that allows NTLM hash leakage via specially crafted .library-ms files. The exploit consists of a Python script (poc_tar.py) that generates a malicious .library-ms file containing an XML payload. This payload references a remote SMB share (attacker-controlled), causing Windows to attempt authentication and leak NTLM credentials when the file is processed. The script then packages the .library-ms file into a .tar archive (exploit.tar), which can be uploaded and extracted on a victim's SMB share using smbclient and the tar command. This method is specifically designed for environments where only SMB access is available, improving compatibility over previous ZIP-based PoCs. The repository includes a README with detailed usage instructions and attack flow. The main attack vector is network-based, leveraging SMB and Windows' handling of .library-ms files to trigger credential leakage. No hardcoded IPs or domains are present; the attacker supplies the target IP at runtime.
This repository provides a proof-of-concept exploit for CVE-2025-24071, a Windows File Explorer spoofing vulnerability. The exploit consists of a Python script (exploit.py) that generates a malicious .library-ms file containing an SMB path to an attacker-controlled server, then packages it into a ZIP archive. When a victim extracts and opens the archive in Windows Explorer, the .library-ms file is automatically parsed, causing the system to initiate an SMB authentication request to the attacker's server, thereby exposing the victim's NTLM hash. The repository includes a README.md with detailed exploitation steps, affected Windows versions, and usage instructions. The main attack vector is network-based, leveraging SMB protocol behavior. The exploit does not provide a weaponized payload but demonstrates the vulnerability's impact by capturing NTLM hashes.
This repository is a proof-of-concept (PoC) exploit for CVE-2025-24054 and CVE-2025-24071, targeting a vulnerability in Windows where opening a specially crafted .library-ms file causes the system to initiate an SMB authentication to an attacker-controlled server, leaking the user's NTLMv2 hash. The repository contains three files: a Python script (exploit.py) that generates a malicious .library-ms file pointing to a configurable SMB server, a sample .library-ms file (xd.library-ms) with a hardcoded attacker IP, and a README with detailed usage instructions. The exploit requires the attacker to run an SMB server (such as Responder) and the victim to open or preview the malicious file. The main attack vector is local file execution leading to a network-based NTLM hash leak. The repository is structured as a PoC and does not include weaponized or automated exploitation features.
This repository provides a Bash script (CVE-2025-24071.sh) that exploits CVE-2025-24071, a Windows File Explorer spoofing vulnerability. The exploit works by generating a malicious .library-ms file that references an SMB share controlled by the attacker. This file is zipped and uploaded to a writable SMB share on the target Windows system using valid credentials. When the target user interacts with the ZIP file and opens the .library-ms file, Windows attempts to access the attacker's SMB share, resulting in the leakage of NTLM hashes. The repository includes a README with detailed usage instructions, a requirements.txt listing dependencies (zip, smbclient), and a LICENSE file. The exploit targets a wide range of Windows 10, 11, and Server versions. The main attack vector is network-based, leveraging SMB protocol interactions. The script automates the creation, packaging, and delivery of the payload, but does not include post-exploitation features or credential cracking. The exploit is a proof-of-concept and requires the attacker to set up an SMB server (e.g., with impacket-smbserver) to capture the leaked credentials.
This repository is a proof-of-concept exploit for CVE-2025-24071 (and related CVE-2025-24054), targeting Microsoft Windows. The main code is a Rust application (src/main.rs) that generates a Windows Library Description (.library-ms) file. The generated file contains an XML payload referencing a network share (\\IP_ADDRESS\shared), where the IP address is supplied via an environment variable (or GitHub secret). The exploit is designed to be run via a GitHub Actions workflow, which automates the process of generating the malicious .library-ms file and uploading it as an artifact. The README provides detailed instructions, references, and a video tutorial. The exploit demonstrates how a crafted .library-ms file can be used to exploit the vulnerability, potentially triggering NTLM authentication or other network-based attacks when the file is opened on a vulnerable Windows system. The repository is structured with a single Rust source file, a GitHub Actions workflow for automation, and supporting documentation. No fake or destructive code is present; the exploit is a minimal, educational proof-of-concept.
This repository provides a proof-of-concept exploit for CVE-2025-24071, a Windows File Explorer spoofing vulnerability. The main exploit logic is implemented in 'loader.py', a Python script that generates a malicious .library-ms file containing a remote SMB path (\\ATTACKER_IP\shared). The script then packages this file into a ZIP archive ('exploit.zip'). When a victim extracts and opens the .library-ms file in Windows Explorer, the system attempts to connect to the attacker's SMB server, leaking the victim's NTLM hash. The repository includes a README with detailed vulnerability information, affected versions, and mitigation advice. The exploit does not include a payload for post-exploitation but demonstrates the vulnerability's impact by causing NTLM hash leakage. The code is simple, requires the attacker to specify an IP address, and is intended for educational and testing purposes only.
This repository provides a proof-of-concept (PoC) exploit for CVE-2025-24071 (renamed CVE-2025-24054), a vulnerability in Microsoft Windows (explorer.exe) that can be abused to leak NetNTLMv2 hashes. The exploit consists of a Python script (PoC.py) that generates a specially crafted .library-ms file referencing an attacker-controlled SMB share (\\<attacker_ip>\shared), then compresses it into a zip archive (exploit.zip). The attacker sends this zip file to a Windows user; when the victim extracts and interacts with the file, Windows attempts to access the specified SMB share, causing the system to send NetNTLMv2 authentication hashes to the attacker's server. The README.md provides usage instructions and context, including the use of Responder to capture the hashes. The repository is structured simply, with one Python exploit script and a README. No detection or fake code is present; the exploit is a working PoC for hash capture via a crafted file and network interaction.
This repository demonstrates a proof-of-concept exploit for CVE-2025-24071, a vulnerability in Microsoft Windows Explorer's handling of .library-ms files inside ZIP archives. The repository contains two files: a README.md with detailed usage instructions and background, and poc.py, a Python script that generates a ZIP file (exploit.zip) containing a malicious .library-ms file. The script takes an attacker's IP address as input and crafts the .library-ms file to reference an SMB share at that address. When a victim extracts the ZIP file on a vulnerable Windows system, Windows Explorer automatically attempts to connect to the attacker's SMB server, leaking the victim's netNTLMv2 credentials. The exploit is a local attack vector requiring the victim to extract the ZIP file, and the attacker must be running an SMB capture tool (such as Responder) to collect the credentials. The exploit is a proof-of-concept and does not include credential cracking or post-exploitation steps.
This repository provides a proof-of-concept (PoC) exploit for CVE-2025-24071, a spoofing vulnerability in Windows File Explorer. The exploit is implemented in Python (exploit.py) and automates the creation of a malicious .library-ms file that references an attacker-controlled SMB share (\\<attacker-ip>\shared). The script then packages this file into a ZIP archive (exploit.zip) for delivery. When a victim extracts and opens the .library-ms file, Windows Explorer will attempt to access the specified SMB share, causing the system to send an SMB authentication request to the attacker's server. This can result in the exposure of the victim's NTLM hash, which can be used for further attacks. The repository includes a README with detailed vulnerability information, affected versions, and mitigation steps. The exploit is a PoC and does not include a server component to capture NTLM hashes; it focuses on generating the malicious file for use in a real-world attack scenario.
This repository is a proof-of-concept (PoC) exploit for CVE-2025-24071, targeting Microsoft Windows systems. It contains a Python script (poc2.py) that generates a specially crafted .searchconnector-ms file. The script prompts the user for an IP address, which is embedded as an SMB network path in the generated file. When a victim opens or interacts with this file on a Windows system, the system attempts to authenticate to the specified SMB share, potentially leaking NTLM credentials to the attacker. The repository also includes a README.md with usage instructions and context. The exploit demonstrates a credential-leak attack vector via a crafted file and does not include any weaponized payload or automation for capturing credentials.
This repository contains a Metasploit auxiliary module (ntlm_hash_leak.rb) that exploits CVE-2025-24071, a vulnerability in Microsoft Windows Explorer. The exploit works by generating a malicious .library-ms file referencing an attacker-controlled SMB share (\\ATTACKER_IP\SHARE_NAME), packaging it into a ZIP archive (exploit.zip), and instructing the attacker to host this file for the victim. When a victim extracts the ZIP file using Windows Explorer, the OS automatically attempts to access the remote SMB share, causing the victim's NTLM hash to be sent to the attacker's SMB capture server. The repository consists of a README.md with detailed usage instructions and the Ruby Metasploit module itself. The exploit is operational, requiring the attacker to configure their IP address and SMB share name, and is designed for use within the Metasploit framework. No hardcoded endpoints are present; the attacker supplies the relevant network parameters at runtime.
This repository demonstrates a proof-of-concept (PoC) exploit for CVE-2025-24071 (updated to CVE-2025-24054), a vulnerability in Microsoft Windows Explorer. The exploit leverages the behavior where extracting a specially crafted .library-ms file from a ZIP archive causes Windows Explorer to automatically initiate an SMB authentication request to a remote server, leaking the user's NTLM hash. The repository contains two files: a README.md with usage instructions and background, and poc.py, a Python script. The script prompts the user for a file name and attacker IP, generates a .library-ms file referencing the attacker's SMB share, packages it into a ZIP archive (exploit.zip), and cleans up the temporary file. The exploit does not require the victim to open or execute the file—simply extracting the ZIP is sufficient to trigger the NTLM hash leak. The main attack vector is local (user interaction with a ZIP file), and the key fingerprintable endpoints are the .library-ms file, the ZIP archive, and the SMB path (\\attacker_ip\shared) used for NTLM hash capture.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Windows Explorer .library-ms vulnerability that leaks NTLM hashes upon extraction, staged with a prebuilt malicious archive for delivery.
Information disclosure vulnerability in Windows File Explorer described as enabling NTLM hash leakage via .library-ms files.
A zero-click vulnerability that allows leaking NTLMv2 hashes, offered for sale by EncryptHub.
A Microsoft Windows File Explorer spoofing vulnerability listed in the summary table.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.