
Cloud Vulnerability DB
An open project to list all known cloud vulnerabilities and Cloud Service Provider security issues
CVE-2025-21377 is a New Technology LAN Manager (NTLM) Hash disclosure spoofing vulnerability that was publicly disclosed prior to a patch being made available. The vulnerability was discovered and reported in February 2025, affecting various versions of Microsoft Windows operating systems (Tenable Blog).
The vulnerability has been assigned a CVSSv3 score of 6.5 (Medium severity). Microsoft has assessed this vulnerability as 'Exploitation More Likely.' The vulnerability requires user interaction, specifically requiring a user to interact with a malicious file by inspecting it or performing actions other than opening or executing the file (Tenable Blog).
Successful exploitation of this vulnerability would allow an attacker to obtain a user's NTLMv2 hash, which could then be used to authenticate as that user (Tenable Blog).
Users need to install the February 2025 security updates to protect against this vulnerability. Additionally, users who only install 'Security Only' updates will also need to install Internet Explorer (IE) Cumulative updates to be fully protected (Tenable Blog).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
An open project to list all known cloud vulnerabilities and Cloud Service Provider security issues
A comprehensive threat intelligence database of cloud security incidents, actors, tools and techniques
A step-by-step framework for modeling and improving SaaS and PaaS tenant isolation
Get a personalized demo
“Best User Experience I have ever seen, provides full visibility to cloud workloads.”
“Wiz provides a single pane of glass to see what is going on in our cloud environments.”
“We know that if Wiz identifies something as critical, it actually is.”