New Windows Zero-Day Exploit: Unofficial Patches Released to Protect NTLM Credentials

Listen to this Post

A New Threat to Windows Users

A newly discovered zero-day vulnerability in Windows allows remote attackers to steal NTLM (NT LAN Manager) credentials simply by tricking victims into viewing malicious files in Windows Explorer. This security flaw affects all versions of Windows, from Windows 7 to the latest Windows 11 releases, as well as Windows Server editions up to 2025.

The vulnerability enables attackers to exploit NTLM authentication, a widely used but increasingly vulnerable protocol. Cybercriminals can use stolen NTLM hashes (encrypted passwords) to gain unauthorized access to sensitive data and spread throughout a network. Microsoft has announced plans to phase out NTLM in future Windows 11 updates, but in the meantime, systems remain at risk.

ACROS Security researchers discovered this vulnerability while working on patches for another NTLM-related flaw. Although this zero-day has not yet received a CVE (Common Vulnerabilities and Exposures) ID, ACROS has released free, unofficial micropatches through its 0Patch service to protect affected Windows users until Microsoft issues an official fix.

the Vulnerability and Its Risks

  • Discovery and Scope: The SCF File NTLM hash disclosure vulnerability was found by ACROS Security researchers. It affects all versions of Windows, including both client and server editions.
  • Exploitation Method: Attackers can steal NTLM credentials by luring users into viewing a malicious file in Windows Explorer. This can occur via a shared network folder, a USB device, or a downloaded file.
  • Real-World Impact: While the exploitability depends on factors such as network access, similar vulnerabilities have been actively used in cyberattacks.
  • Mitigation Measures: ACROS Security has released micropatches for free via its 0Patch service, providing protection until Microsoft releases an official fix.

How to Apply the 0Patch Micropatch

To install the micropatch and safeguard your system:

1. Create an account on the 0Patch platform.

  1. Download and install the 0Patch agent on your Windows PC.
  2. The agent will automatically apply the patch without requiring a system restart.

0Patch has previously identified and released micropatches for several other NTLM-related vulnerabilities, including:

– CVE-2025-21308 – A Windows Theme vulnerability.

  • CVE-2025-21377 – A URL File NTLM Hash Disclosure vulnerability.
  • Other NTLM flaws – PetitPotam, PrinterBug/SpoolSample, and DFSCoerce, which remain unpatched by Microsoft.

Microsoft has yet to provide an official statement on the newly discovered vulnerability.

What Undercode Say: A Deeper Analysis of the Threat

NTLM’s Ongoing Security Risks

NTLM authentication has long been a target for attackers, particularly in relay attacks and pass-the-hash attacks. In these scenarios, hackers can bypass traditional login mechanisms by capturing and reusing NTLM hashes. Microsoft has acknowledged NTLM’s weaknesses and plans to retire the protocol in future Windows versions. However, as this vulnerability shows, NTLM remains a significant security risk today.

How This Vulnerability Works

Unlike traditional exploits that require opening a file or clicking a link, this zero-day flaw allows attackers to steal credentials simply by having the victim view a malicious file in Windows Explorer. This makes it particularly dangerous because:
– It does not require execution of malicious code.
– It can be triggered via network shares, USB drives, or downloads.
– It can be used as part of a larger attack chain, allowing hackers to infiltrate networks.

The Role of 0Patch in Rapid Response Security

Microsoft often takes weeks or months to release official security patches, leaving users exposed to active threats. 0Patch plays a crucial role in the cybersecurity community by providing micropatches—small, temporary fixes that can be applied instantly. The company has repeatedly stepped in to patch Windows vulnerabilities before Microsoft’s official response.

Potential Exploitation Scenarios

  • Corporate Networks: If an attacker gains access to a shared folder in an enterprise environment, they could steal NTLM credentials from multiple employees, allowing them to escalate privileges.
  • Public-Facing Servers: Attackers could exploit this flaw on servers with external connections, using stolen hashes to infiltrate the network.
  • Phishing Campaigns: Malicious actors could distribute files through email attachments, file-sharing platforms, or drive-by downloads.

Microsoft’s Security Strategy: A Step Too Late?

Microsoft’s delay in addressing NTLM vulnerabilities raises concerns about its security response. While the company plans to phase out NTLM, many businesses still rely on it for authentication. The lack of an immediate official patch increases the risk for Windows users, highlighting the need for proactive security solutions like 0Patch.

How Users Can Protect Themselves

  1. Apply the 0Patch Micropatch – This is the fastest way to mitigate the risk.
  2. Disable NTLM Authentication – If possible, switch to more secure authentication protocols like Kerberos.
  3. Monitor Network Traffic – Use security tools to detect unusual NTLM authentication attempts.
  4. Be Cautious with Untrusted Files – Avoid opening unknown network shares, USB drives, or suspicious downloads.

Fact Checker Results

  1. The NTLM vulnerability is real and actively being patched by 0Patch, but Microsoft has not yet issued an official fix.
  2. This zero-day does not require file execution—just viewing the file in Windows Explorer can trigger the attack.
  3. Microsoft has acknowledged NTLM’s weaknesses and plans to retire the protocol, but it remains a widely used authentication method.

This vulnerability underscores the ongoing risks of outdated authentication systems and the importance of third-party security patches in protecting users before official fixes are available.

References:

Reported By: https://www.bleepingcomputer.com/news/security/new-windows-zero-day-leaks-ntlm-hashes-gets-unofficial-patch/
Extra Source Hub:
https://www.linkedin.com
Wikipedia
Undercode AI

Image Source:

Pexels
Undercode AI DI v2

Join Our Cyber World:

💬 Whatsapp | 💬 TelegramFeatured Image