
NTLM is widely used in NTLM relay attacks (hackers coerce vulnerable network devices to authenticate to servers under their control) and in pass-the-hash attacks (vulnerabilities are exploited to steal NTLM hashes).
After such attacks, cybercriminals typically use stolen hashes to authenticate on behalf of compromised users to gain access to sensitive data and perform lateral movement on the network.
This is why Microsoft announced last year that the NTLM authentication protocol won’t be supported in future versions of Windows 11.
This week, Acros Security reported the discovery of a SCF File NTLM Hash Disclosure Vulnerability (zero-day) resulting in NTLM hash leaks. The issue was identified while patching another vulnerability also related to hash disclosure.
The new zero-day vulnerability doesn’t have a CVE identifier yet. The bug affects all versions of Windows: from Windows 7 to the latest versions of Windows 11 and from Server 2008 R2 to Server 2025.
” The vulnerability allows an attacker to obtain user’s NTLM credentials by having the user view a malicious file in Windows Explorer – e.g., by opening a shared folder or USB disk with such file, or viewing the Downloads folder where such file was previously automatically downloaded from attacker’s web page. While these types of vulnerabilities are not critical and their exploitability depends on several factors (e.g., the attacker either already being in the victim’s network or having an external target like a public-facing Exchange server to relay the stolen credentials to), they have been found to be used in actual attacks,” – Mitja Kolsek, Acros Security CEO.
No further details of the newly-discovered vulnerability were disclosed to minimize potential exploitation risks. Experts have already submitted all the information to Microsoft, and its engineers are already working on a fix.
Acros Security has already issued unofficial micropatches for all versions of Windows; they can be applied pending the release of an official patch fixing this bug. The free micropatches are available to users of the 0patch service.
To remind, 0patch by Acros Security is a platform designed specifically to protect users against 0day and ‘wont fix’ vulnerabilities and maintain legacy products no longer supported by their manufacturers.
According to Microsoft, the company is aware of the newly-discovered security hole, and it takes all required steps to protect its customers.

2025.03.16 — Researchers force DeepSeek to write malware
According to Tenable, the AI chatbot DeepSeek R1 from China can be used to write malware (e.g. keyloggers and ransomware). DeepSeek was released in January 2025 and caused a stir…
Full article →
2025.04.04 — Privilege escalation vulnerability in Google Cloud resulting in sensitive data leaks finally patched
Tenable Research revealed details of a recently patched privilege escalation vulnerability in Google Cloud Platform (GCP) Cloud Run enabling an attacker to gain access to container images…
Full article →
2025.02.10 — Failed attempt to block phishing link results in massive Cloudflare outage
According to the incident report released by Cloudflare, an attempt to block a phishing URL on the R2 platform accidentally caused a massive outage; as a result, many Cloudflare…
Full article →
2025.01.24 — Hundreds of websites impersonating Reddit and WeTransfer spread Lumma Stealer
Sekoia researcher crep1x discovered that hackers are currently using some 1,000 pages impersonating Reddit and WeTransfer. Victims visiting these sites are tricked into…
Full article →
2025.01.25 — 18,000 script kiddies have been infected with backdoor via XWorm RAT builder
According to CloudSEK analysts, malefactors attack novice hackers using a fake malware builder. Script kiddies' systems become infected with a backdoor that steals data and subsequently…
Full article →
2025.04.25 — Asus patches vulnerability in AMI's MegaRAC enabling attackers to brick servers
Asus released patches for the CVE-2024-54085 vulnerability that allows attackers to seize and disable servers. The security hole affects the American Megatrends International (AMI) MegaRAC Baseboard Management…
Full article →
2025.04.22 — Scammers pose as FBI IC3 specialists, offer 'assistance' to fraud victims
According to the FBI, scammers impersonating employees of the FBI Internet Fraud Complaint Center (IC3) contact fraud victims offering them 'assistance' in getting their money…
Full article →
2025.02.23 — New JavaScript obfuscation technique uses invisible Unicode characters
According to Juniper Threat Labs , a new JavaScript obfuscation technique that uses invisible Unicode characters was used in a phishing attack targeting Political Action…
Full article →
2025.01.28 — J-magic backdoor attacked Juniper Networks devices using 'magic packets'
A massive backdoor attack targeting Juniper routers often used as VPN gateways has been uncovered. The devices were attacked by the J-magic malware that…
Full article →
2025.03.20 — 8,000 vulnerabilities identified in WordPress ecosystem in 2024
According to Patchstack, world's #1 WordPress vulnerability intelligence provider, 7,966 new vulnerabilities were identified in the WordPress ecosystem in 2024; most of these bugs affected plugins…
Full article →