It Risk

Microsoft NTLM Zero-Day to Remain Unpatched Until April

Share:

The second zero-day vulnerability found in Windows NTLM in the past two months paves the way for relay attacks and credential theft. Microsoft has no patch, but released updated NTLM cyberattack mitigation advice.

Microsoft has released fresh guidance to organizations on how to mitigate NTLM relay attacks by default, days after researchers reported finding a NTLM hash disclosure zero-day in all versions of Windows Workstation and Server, from Windows 7 to current Windows 11 versions.

However, it was not immediately clear if the two developments are related or purely coincidental in terms of timing. In any event, the bug, which doesn’t yet have a CVE or CVSS score, is not expected to be patched for months.

Windows NTLM Zero-Day Allows Credential Theft

Researchers from ACROS Security reported finding a zero-day bug in all supported Windows versions. The bug allows an attacker to grab a user’s NTLM credentials simply by getting the user to view a malicious file via the Windows Explorer file management utility.

“Opening a shared folder or USB disk with such file or viewing the Downloads folder where such file was previously automatically downloaded from attacker’s Web page” is all it takes for credential compromise, Mitja Kolsek, CEO of ACROS Security wrote in a blog post.

ACROS said it would not release any further information on the bug until Microsoft has a fix for it. But Kolsek tells Dark Reading that an attacker’s ability to exploit the bug depends on various factors.

“It’s not easy to find where the issue is exploitable without actually trying to exploit it,” he explains. Microsoft has assessed the vulnerability as being of moderate or “Important” severity, a designation that is one notch lower than “Critical” severity bugs. The company plans to issue a fix for it in April, Kolsek says.

In an emailed comment, a Microsoft spokesman said the company is “aware of the report and will take action as needed to help keep customers protected.”

The bug is the second NTLM credential leak zero-day that ACROS has reported to Microsoft since October. The previous one involved a Windows Themes spoofing issue and allowed attackers a way to coerce victim devices into sending NTLM authentication hashes to attacker-controlled devices. Microsoft has not yet issued a patch for that bug either.

The bugs are among several NTLM-related issues that have surfaced in recent years including PetitPotam, DFSCoerce, PrinterBug/SpoolSample, and, recently, one affecting the open source policy enforcement engine.

Legacy Protocol Dangers

Windows NTLM (NT LAN Manager) is a legacy authentication protocol that Microsoft includes in modern Windows for backward compatibility purposes. Attackers have frequently targeted weaknesses in the protocol to intercept authentication requests and forward or “relay” them to access other servers or services to which the original users have access.

In its advisory this week, Microsoft described NTLM-relaying as a “popular attack method used by threat actors that allows for identity compromise.” The attacks involve coercing a victim to authenticate to an attacker-controlled endpoint and relaying the authentication against a vulnerable target server or service. The advisory pointed to vulnerabilities that attackers have used previously, such as CVE-2023-23397 in Outlook and CVE-2021-36942 in Windows LSA, to exploit service that lack protections against NTLM-relaying attacks.

In response to such attacks, Microsoft has updated previous guidance on how to enable Extended Protection for Authentication (EPA) by default on LDAP, AD CS, and Exchange Server, the company said. The latest Windows Server 2025 ships with EPA enabled by default for both AD CS and LDAP.

The advisory highlighted the need for organizations to enable EPA specially for Exchange Server, given the “unique role that Exchange Server plays in the NTLM threat landscape.” The company pointed to CVE-2024-21413CVE-2023-23397, and CVE-2023-36563 as examples of recent vulnerabilities that attackers have exploited for NTLM coercion purposes. “Office documents and emails sent through Outlook serve as effective entry points for attackers to exploit NTLM coercion vulnerabilities, given their ability to embed UNC links within them,” the company says.

Kolsek says it’s unclear if Microsoft’s advice for protecting against NTLM attacks has anything to do with his recent bug disclosure. “[But] if possible, follow Microsoft’s recommendations on mitigating NTLM-related vulnerabilities,” he says. “If not, consider 0patch,” he adds, referring to the free micropatches that his company provides for vulnerabilities, especially in older and no longer supported software products.

Source

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
11:25 am, Apr 20, 2025
weather icon 12°C
L: 11° | H: 13°
scattered clouds
Humidity: 65 %
Pressure: 1007 mb
Wind: 5 mph ENE
Wind Gust: 13 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 29%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 5:53 am
Sunset: 8:04 pm
DailyHourly
Daily ForecastHourly Forecast
Today 10:00 pm
weather icon
11° | 13°°C 0.2 mm 20% 9 mph 83 % 1008 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
10° | 13°°C 1 mm 100% 5 mph 93 % 1013 mb 0 mm/h
Tue Apr 22 10:00 pm
weather icon
7° | 16°°C 0.2 mm 20% 11 mph 91 % 1018 mb 0 mm/h
Wed Apr 23 10:00 pm
weather icon
9° | 14°°C 1 mm 100% 12 mph 91 % 1015 mb 0 mm/h
Thu Apr 24 10:00 pm
weather icon
8° | 15°°C 0.2 mm 20% 8 mph 85 % 1023 mb 0 mm/h
Today 1:00 pm
weather icon
14° | 16°°C 0 mm 0% 9 mph 62 % 1007 mb 0 mm/h
Today 4:00 pm
weather icon
14° | 15°°C 0 mm 0% 6 mph 62 % 1006 mb 0 mm/h
Today 7:00 pm
weather icon
13° | 13°°C 0 mm 0% 6 mph 73 % 1007 mb 0 mm/h
Today 10:00 pm
weather icon
11° | 11°°C 0.2 mm 20% 6 mph 83 % 1008 mb 0 mm/h
Tomorrow 1:00 am
weather icon
11° | 11°°C 0 mm 0% 3 mph 87 % 1008 mb 0 mm/h
Tomorrow 4:00 am
weather icon
10° | 10°°C 0 mm 0% 2 mph 87 % 1007 mb 0 mm/h
Tomorrow 7:00 am
weather icon
10° | 10°°C 0 mm 0% 1 mph 89 % 1008 mb 0 mm/h
Tomorrow 10:00 am
weather icon
10° | 10°°C 0.73 mm 73% 1 mph 93 % 1009 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€74,250.74
-0.97%
Ethereum(ETH)
€1,398.90
-0.52%
Tether(USDT)
€0.88
0.00%
XRP(XRP)
€1.81
-1.23%
Solana(SOL)
€122.56
-0.22%
USDC(USDC)
€0.88
-0.01%
Dogecoin(DOGE)
€0.136479
-1.86%
Shiba Inu(SHIB)
€0.000011
0.57%
Pepe(PEPE)
€0.000006
2.11%
Scroll to Top