POC CVE-2025-24071
by caca28sapo1 - Thursday April 10, 2025 at 07:51 PM
#1
Windows Explorer automatically initiates an SMB authentication request when a .library-ms file is extracted from a .rar archive, leading to NTLM hash disclosure. The user does not need to open or execute the file—simply extracting it is enough to trigger the leak.

usage:

>>python poc.py

>>enter file name: your file name

>>enter IP: attacker IP

Link:
Hidden Content
You must register or login to view this content.

Reply
#2
Thanks, this worked for me
Reply
#3
nice mind blowing content from u brother
Reply
#4
Thanks, will give this a try!
If I end up writing anything myself I will create a new thread and credit you.
Reply
#5
Thank you! I will give it a try
Reply
#6
Thanks for sharing, not seen this one before
Reply
#7
Thank you for poc
Reply
#8
Thanks for sharing, lemme check
Reply
#9
Thank you very much. I really need this.
Reply
#10
I don’t know abt that
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  CVE-2025-29927 - POC loganpaul09 26 1,175 08-06-2025, 01:12 PM
Last Post: Fuc0
  Nginx RCE - 2025 - March loganpaul09 5 441 08-04-2025, 01:58 AM
Last Post: CLOBELSECTEAM
  CVE-2025-47812 - Wing FTP Server Remote Code Execution (RCE) thermos 7 364 08-03-2025, 08:21 PM
Last Post: handsomexxxxxy
  !Next.js Middleware Bypass (CVE-2025-29927) Rat1337 16 747 08-03-2025, 11:17 AM
Last Post: icebear223
  CVE-2025-53770 - Microsoft Sharepoint Unauthenticated RCE antisocial 1 178 07-28-2025, 10:50 AM
Last Post: Krypt3d4ng3l

Forum Jump:


 Users browsing this thread: