CVE-2025-21377
vulnerability analysis and mitigation

Overview

CVE-2025-21377 is a New Technology LAN Manager (NTLM) Hash disclosure spoofing vulnerability that was publicly disclosed prior to a patch being made available. The vulnerability was discovered and reported in February 2025, affecting various versions of Microsoft Windows operating systems (Tenable Blog).

Technical details

The vulnerability has been assigned a CVSSv3 score of 6.5 (Medium severity). Microsoft has assessed this vulnerability as 'Exploitation More Likely.' The vulnerability requires user interaction, specifically requiring a user to interact with a malicious file by inspecting it or performing actions other than opening or executing the file (Tenable Blog).

Impact

Successful exploitation of this vulnerability would allow an attacker to obtain a user's NTLMv2 hash, which could then be used to authenticate as that user (Tenable Blog).

Mitigation and workarounds

Users need to install the February 2025 security updates to protect against this vulnerability. Additionally, users who only install 'Security Only' updates will also need to install Internet Explorer (IE) Cumulative updates to be fully protected (Tenable Blog).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

“Best User Experience I have ever seen, provides full visibility to cloud workloads.”
David EstlickCISO
“Wiz provides a single pane of glass to see what is going on in our cloud environments.”
Adam FletcherChief Security Officer
“We know that if Wiz identifies something as critical, it actually is.”
Greg PoniatowskiHead of Threat and Vulnerability Management