CVE-2024-43451: Microsoft Windows NTLMv2 Hash Disclosure Spoofing
Microsoft Windows NTLMv2 Hash Disclosure Spoofing Vulnerability. Microsoft Windows contains an NTLMv2 hash spoofing vulnerability that could result in disclosing a user's NTLMv2 hash to an attacker via a file open operation. The attacker could then leverage this hash to impersonate that user.
- CISA KEV-listed (remediation due 2024-12-03)
- EPSS 90.3% (99.6% percentile)