CVE-2025-24071

MEDIUM EXPLOITED

Microsoft Windows 10 1507 < 10.0.10240.20947 - Information Disclosure

Title source: rule

Description

Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an unauthorized attacker to perform spoofing over a network.

Exploits (32)

exploitdb WORKING POC
by Daniel Miranda · pythonremotewindows
https://www.exploit-db.com/exploits/52325
exploitdb WORKING POC
by Mohammed Idrees Banyamer · pythonremotewindows
https://www.exploit-db.com/exploits/52310
nomisec WORKING POC 396 stars
by 0x6rss · client-side
https://github.com/0x6rss/CVE-2025-24071_PoC
nomisec WORKING POC 28 stars
by ThemeHackers · infoleak
https://github.com/ThemeHackers/CVE-2025-24071
nomisec WORKING POC 26 stars
by FOLKS-iwd · client-side
https://github.com/FOLKS-iwd/CVE-2025-24071-msfvenom
nomisec WORKING POC 25 stars
by Marcejr117 · client-side
https://github.com/Marcejr117/CVE-2025-24071_PoC
github WORKING POC 21 stars
by helidem · pythonclient-side
https://github.com/helidem/CVE-2025-24054_CVE-2025-24071-PoC
nomisec WORKING POC 4 stars
by TH-SecForge · client-side
https://github.com/TH-SecForge/CVE-2025-24071
github WORKING POC 3 stars
by basekilll · pythonpoc
https://github.com/basekilll/CVE-2025-24054_PoC
github WORKING POC 2 stars
by adminlove520 · pythonpoc
https://github.com/adminlove520/CVE-Poc_All_in_One/tree/main/2025/CVE-2025-24071
nomisec WORKING POC 2 stars
by fsoc-ghost-0x · client-side
https://github.com/fsoc-ghost-0x/Fsociety-CVE-2025-24071-NTLM-Coercion
nomisec WORKING POC 2 stars
by ctabango · infoleak
https://github.com/ctabango/CVE-2025-24071_PoCExtra
nomisec WORKING POC 2 stars
by ex-cal1bur · client-side
https://github.com/ex-cal1bur/SMB_CVE-2025-24071
nomisec WORKING POC 2 stars
by LOOKY243 · client-side
https://github.com/LOOKY243/CVE-2025-24071-PoC
nomisec WORKING POC 1 stars
by DeshanFer94 · client-side
https://github.com/DeshanFer94/CVE-2025-24071-POC-NTLMHashDisclosure-
nomisec WORKING POC 1 stars
by t0x1nsec · poc
https://github.com/t0x1nsec/Windows-Explorer-CVE-2025-24071
nomisec WORKING POC 1 stars
by cesarbtakeda · client-side
https://github.com/cesarbtakeda/Windows-Explorer-CVE-2025-24071
nomisec WORKING POC 1 stars
by rubbxalc · client-side
https://github.com/rubbxalc/CVE-2025-24071
gitlab WORKING POC
by ThemeHackers · poc
https://gitlab.com/ThemeHackers/CVE-2025-24071
nomisec WORKING POC
by Abdelrahman0Sayed · infoleak
https://github.com/Abdelrahman0Sayed/CVE-2025-24071
github STUB
by Wind010 · poc
https://github.com/Wind010/CVE-2025-24054_PoC
nomisec WORKING POC
by AC8999 · poc
https://github.com/AC8999/CVE-2025-24071
nomisec WORKING POC
by Royall-Researchers · client-side
https://github.com/Royall-Researchers/CVE-2025-24071
nomisec WORKING POC
by f4dee-backup · client-side
https://github.com/f4dee-backup/CVE-2025-24071
nomisec WORKING POC
by zbs54 · poc
https://github.com/zbs54/Blackash-CVE-2025-24071
nomisec WORKING POC
by pswalia2u · client-side
https://github.com/pswalia2u/CVE-2025-24071_POC
nomisec WORKING POC
by ephunter · poc
https://github.com/ephunter/CVE-2025-24071-Exploit
nomisec NO CODE
by aleongx · poc
https://github.com/aleongx/CVE-2025-24071
patchapalooza WORKING POC
by xigney · client-side
https://github.com/xigney/CVE-2025-24054_PoC

Scores

CVSS v3 6.5
EPSS 0.7389
EPSS Percentile 98.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

Details

VulnCheck KEV 2025-04-03
CWE
CWE-200
Status published
Products (11)
microsoft/windows_10_1507 < 10.0.10240.20947 (2 CPE variants)
microsoft/windows_10_1607 < 10.0.14393.7876 (2 CPE variants)
microsoft/windows_10_1809 < 10.0.17763.7009 (2 CPE variants)
microsoft/windows_11_23h2 < 10.0.22631.5039
microsoft/windows_11_24h2 < 10.0.26100.3476 (2 CPE variants)
microsoft/windows_server_2012 r2
microsoft/windows_server_2016 < 10.0.14393.7876
microsoft/windows_server_2019 < 10.0.17763.7009
microsoft/windows_server_2022 < 10.0.20348.3328
microsoft/windows_server_2022_23h2 < 10.0.25398.1486
... and 1 more
Published Mar 11, 2025
Tracked Since Feb 18, 2026