CVE-2025-24071 - NTLM Hash Leak via RAR/ZIP Extraction and .library-ms File

0 Replies, 435 Views

Windows Explorer automatically initiates an SMB authentication request when a .library-ms file is extracted from a .rar archive, leading to NTLM hash disclosure. The user does not need to open or execute the file—simply extracting it is enough to trigger the leak.

blog post:
You are not allowed to view links. Register or Login to view.

POC: You are not allowed to view links. Register or Login to view.

>>python poc.py

>>enter file name: your file name

>>enter IP: attacker IP
[Image: e72398fe92beda2aa80d0329e8b9f4febece7568.gif]



Users browsing this thread: 1 Guest(s)