No Result
View All Result
Global Finances Daily
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers
No Result
View All Result
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers
  • Login
Global Finances Daily
No Result
View All Result
Home Protection

Microsoft NTLM Zero-Day to Remain Unpatched Until April

December 9, 2024
in Protection
0
Microsoft NTLM Zero-Day to Remain Unpatched Until April


Microsoft has released fresh guidance to organizations on how to mitigate NTLM relay attacks by default, days after researchers reported finding a NTLM hash disclosure zero-day in all versions of Windows Workstation and Server, from Windows 7 to current Windows 11 versions.

However, it was not immediately clear if the two developments are related or purely coincidental in terms of timing. In any event, the bug, which doesn’t yet have a CVE or CVSS score, is not expected to be patched for months.

Windows NTLM Zero-Day Allows Credential Theft

Researchers from ACROS Security reported finding a zero-day bug in all supported Windows versions. The bug allows an attacker to grab a user’s NTLM credentials simply by getting the user to view a malicious file via the Windows Explorer file management utility.

“Opening a shared folder or USB disk with such file or viewing the Downloads folder where such file was previously automatically downloaded from attacker’s Web page” is all it takes for credential compromise, Mitja Kolsek, CEO of ACROS Security wrote in a blog post.

ACROS said it would not release any further information on the bug until Microsoft has a fix for it. But Kolsek tells Dark Reading that an attacker’s ability to exploit the bug depends on various factors.

“It’s not easy to find where the issue is exploitable without actually trying to exploit it,” he explains. Microsoft has assessed the vulnerability as being of moderate or “Important” severity, a designation that is one notch lower than “Critical” severity bugs. The company plans to issue a fix for it in April, Kolsek says.

In an emailed comment, a Microsoft spokesman said the company is “aware of the report and will take action as needed to help keep customers protected.”

The bug is the second NTLM credential leak zero-day that ACROS has reported to Microsoft since October. The previous one involved a Windows Themes spoofing issue and allowed attackers a way to coerce victim devices into sending NTLM authentication hashes to attacker-controlled devices. Microsoft has not yet issued a patch for that bug either.

The bugs are among several NTLM-related issues that have surfaced in recent years including PetitPotam, DFSCoerce, PrinterBug/SpoolSample, and, recently, one affecting the open source policy enforcement engine.

Legacy Protocol Dangers

Windows NTLM (NT LAN Manager) is a legacy authentication protocol that Microsoft includes in modern Windows for backward compatibility purposes. Attackers have frequently targeted weaknesses in the protocol to intercept authentication requests and forward or “relay” them to access other servers or services to which the original users have access.

In its advisory this week, Microsoft described NTLM-relaying as a “popular attack method used by threat actors that allows for identity compromise.” The attacks involve coercing a victim to authenticate to an attacker-controlled endpoint and relaying the authentication against a vulnerable target server or service. The advisory pointed to vulnerabilities that attackers have used previously, such as CVE-2023-23397 in Outlook and CVE-2021-36942 in Windows LSA, to exploit service that lack protections against NTLM-relaying attacks.

In response to such attacks, Microsoft has updated previous guidance on how to enable Extended Protection for Authentication (EPA) by default on LDAP, AD CS, and Exchange Server, the company said. The latest Windows Server 2025 ships with EPA enabled by default for both AD CS and LDAP.

The advisory highlighted the need for organizations to enable EPA specially for Exchange Server, given the “unique role that Exchange Server plays in the NTLM threat landscape.” The company pointed to CVE-2024-21413, CVE-2023-23397, and CVE-2023-36563 as examples of recent vulnerabilities that attackers have exploited for NTLM coercion purposes. “Office documents and emails sent through Outlook serve as effective entry points for attackers to exploit NTLM coercion vulnerabilities, given their ability to embed UNC links within them,” the company says.

Kolsek says it’s unclear if Microsoft’s advice for protecting against NTLM attacks has anything to do with his recent bug disclosure. “[But] if possible, follow Microsoft’s recommendations on mitigating NTLM-related vulnerabilities,” he says. “If not, consider 0patch,” he adds, referring to the free micropatches that his company provides for vulnerabilities, especially in older and no longer supported software products.



Editorial Team

Editorial Team

Related Posts

Sony's Newest Earbuds Are Clip-Ons
Protection

Sony’s Newest Earbuds Are Clip-Ons

January 21, 2026
How to Tap Into a 'Flow State' In Your Workouts
Protection

How to Tap Into a ‘Flow State’ In Your Workouts

January 21, 2026
The Razer Kishi Ultra Gaming Controller Is Nearly 50% Off Right Now
Protection

The Razer Kishi Ultra Gaming Controller Is Nearly 50% Off Right Now

January 21, 2026
Digg Is Back | Lifehacker
Protection

Digg Is Back | Lifehacker

January 21, 2026
Scammers Are Targeting Your Verizon Outage Refund
Protection

Scammers Are Targeting Your Verizon Outage Refund

January 20, 2026
ChatGPT Is Getting on the AI Age Verification Bandwagon
Protection

ChatGPT Is Getting on the AI Age Verification Bandwagon

January 20, 2026
Load More
Next Post
Rivian stock jumps to highest since August as Benchmark initiates at Buy

Rivian stock jumps to highest since August as Benchmark initiates at Buy

Popular News

  • Josh Garber

    How to Contact Hilton Customer Service

    0 shares
    Share 0 Tweet 0
  • Cybersecurity dominates concerns among the C-suite, small businesses and the nation

    0 shares
    Share 0 Tweet 0
  • Chainalysis Launches No-Code Automation Workflows For Blockchain Intelligence

    0 shares
    Share 0 Tweet 0
  • 5 Things to Know About the Seen Mastercard

    0 shares
    Share 0 Tweet 0
  • Cash Sweep Accounts vs. Money Market Funds, HYSAs & CDs

    0 shares
    Share 0 Tweet 0

Latest News

Iran deaths went beyond protesters, hitting bystanders too, witnesses say

Iran deaths went beyond protesters, hitting bystanders too, witnesses say

January 21, 2026
0

Iran deaths went beyond protesters, hitting bystanders too, witnesses say

Barings and Partners Group agree deal

Barings provides $365m of loans for Partners Group evergreen fund

January 21, 2026
0

Barings and Partners Group have agreed a $365m (£271.8m) financing partnership, whereby Barings will provide investment-grade rated loans for Partners...

Turns out, DOGE did put Social Security data at risk. Here’s what lawmakers are doing about it.

Turns out, DOGE did put Social Security data at risk. Here’s what lawmakers are doing about it.

January 21, 2026
0

Trump administration admits to security breaches that had been outlined in a whistleblower complaint

Crypto

Senate Ag Committee To Release Latest Crypto Market Structure Bill Draft Today

January 21, 2026
0

Trusted Editorial content, reviewed by leading industry experts and seasoned editors. Ad Disclosure The Senate Banking Committee delayed the anticipated...

Global Finances Daily

Welcome to Global Finances Daily, your go-to source for all things finance. Our mission is to provide our readers with valuable information and insights to help them achieve their financial goals and secure their financial future.

Subscribe

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Use
  • Editorial Process

© 2025 All Rights Reserved - Global Finances Daily.

No Result
View All Result
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers

© 2025 All Rights Reserved - Global Finances Daily.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.