CVE-2024-43451: Microsoft Windows NTLMv2 Hash Disclosure Spoofing Vulnerability
Microsoft Windows contains an NTLMv2 hash spoofing vulnerability that could result in disclosing a user's NTLMv2 hash to an attacker via a file open operation. The attacker could then leverage this hash to impersonate that user.
Other sources
NTLM Hash Disclosure Spoofing Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.17763.6532Patch KB5046615 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.0.6003.22966Fixed in 1.001Patch KB5046630 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26100.2314Fixed in 10.0.26100.2240Patch KB5046696 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.1.7601.27415Fixed in 1.001Patch KB5046630 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.3.9600.22267Fixed in 1.001Patch KB5046630 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.14393.7515Patch KB5046612 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.10240.20826Patch KB5046665 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22631.4460Patch KB5046633 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.25398.1251Patch KB5046618 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19045.5131Patch KB5046613 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22621.4460Patch KB5046633 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.20348.2849Fixed in 10.0.20348.2819Patch KB5046698 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19044.5131Patch KB5046613
Event History
Frequently Asked Questions
What is the severity of CVE-2024-43451?
CVE-2024-43451 has a high severity rating due to the potential for NTLMv2 hash disclosure that can lead to user impersonation.
How do I fix CVE-2024-43451?
To mitigate CVE-2024-43451, apply the latest security patches provided by Microsoft for the affected Windows versions.
Which versions of Windows are affected by CVE-2024-43451?
CVE-2024-43451 affects various Windows versions including Windows 10 (all supported versions), Windows Server 2019, Windows 11, and Windows Server 2022.
How can an attacker exploit CVE-2024-43451?
An attacker can exploit CVE-2024-43451 by tricking users into performing file operations that inadvertently disclose their NTLMv2 password hashes.
Is there a workaround for CVE-2024-43451?
While the recommended solution is to apply updates, if immediate patching is not possible, limiting access to vulnerable file operations may serve as a temporary workaround.