CVE-2025-29745: Infoleak
Published Aug 5, 2025
·Updated
A vulnerability affecting the scanning module in Emsisoft Anti-Malware prior to 2024.12 allows attackers on a remote server to obtain Net-NTLMv2 hash information via a specially created A2S (Emsisoft Custom Scan) extension file.
Affected Software
1 affected component
Emsisoft Anti-Malware<2024.12
Event History
Aug 5, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-29745?
CVE-2025-29745 is considered a critical vulnerability due to its potential to expose sensitive authentication data.
2
How do I fix CVE-2025-29745?
To fix CVE-2025-29745, upgrade Emsisoft Anti-Malware to version 2024.12 or later.
3
What type of attack can CVE-2025-29745 facilitate?
CVE-2025-29745 can facilitate remote attackers obtaining Net-NTLMv2 hash information.
4
Which versions of Emsisoft Anti-Malware are affected by CVE-2025-29745?
Emsisoft Anti-Malware versions prior to 2024.12 are affected by CVE-2025-29745.
5
Is there a workaround for CVE-2025-29745?
There is no known workaround for CVE-2025-29745, so upgrading is recommended.