CVE-2024-43609
MEDIUMMicrosoft 365 Apps and Office - Exposure of Sensitive Information via Spoofing
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2024-43609. PoCs published by passtheticket.
AI-analyzed exploit summary The repository contains a functional exploit for CVE-2024-43609, which leverages Office URI schemes to capture NTLMv2 hashes over HTTP via a 302 redirect to a UNC path. The `uncredirect.py` script facilitates this attack by redirecting HTTP requests to a Responder-controlled UNC path, enabling NTLM relay attacks.
Description
Microsoft Office Spoofing Vulnerability
Exploits (1)
The repository contains a functional exploit for CVE-2024-43609, which leverages Office URI schemes to capture NTLMv2 hashes over HTTP via a 302 redirect to a UNC path. The `uncredirect.py` script facilitates this attack by redirecting HTTP requests to a Responder-controlled UNC path, enabling NTLM relay attacks.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N