CVE-2024-43451CISA KEV
Microsoft Windows NTLMv2 Hash Disclosure Spoofing Vulnerability
CISA lists this Microsoft vulnerability as known exploited. Its MSRC release detail is outside this installation's collected history.
CISA catalog record
Microsoft Windows contains an NTLMv2 hash spoofing vulnerability that could result in disclosing a user's NTLMv2 hash to an attacker via a file open operation. The attacker could then leverage this hash to impersonate that user.
- Product
- Windows
- Added to KEV
- 12 Nov 2024
- Federal remediation due
- 3 Dec 2024
- Known ransomware use
- Not reported