CVE-2025-54918
HIGHWindows 10 1507-22H2, Windows 11 22H2-24H2, Windows Server 2008 - Privilege Escalation via NTLM Authentication
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2025-54918. PoCs published by Wh0am123, mrk336.
AI-analyzed exploit summary This PoC demonstrates an NTLM relay attack combined with authentication coercion to escalate from a low-privileged domain user to Domain Admin via LDAP manipulation, even with SMB signing enabled. It leverages CVE-2025-54918 to achieve DCSync and full domain compromise.
Description
Improper authentication in Windows NTLM allows an authorized attacker to elevate privileges over a network.
Exploits (2)
This PoC demonstrates an NTLM relay attack combined with authentication coercion to escalate from a low-privileged domain user to Domain Admin via LDAP manipulation, even with SMB signing enabled. It leverages CVE-2025-54918 to achieve DCSync and full domain compromise.
This repository is a writeup detailing the exploitation and mitigation of CVE-2025-54918, an NTLM authentication bypass vulnerability in Windows. It includes detection scripts, Ansible playbooks for patching, and CI/CD integration examples, but does not contain functional exploit code.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H