CVE-2025-52488: DNN.PLATFORM leaks NTLM hash via SMB Share Interaction with malicious user input
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. In versions 6.0.0 to before 10.0.1, DNN.PLATFORM allows a specially crafted series of malicious interaction to potentially expose NTLM hashes to a third party SMB server. This issue has been patched in version 10.0.1.
Other sources
DNN.PLATFORM allows a specially crafted series of malicious interaction can expose NTLM hashes to a third party SMB server. This vulnerability is fixed in 10.0.1.
— GitHub
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-52488?
CVE-2025-52488 has a high severity rating due to the potential exposure of NTLM hashes.
How do I fix CVE-2025-52488?
To fix CVE-2025-52488, upgrade DNN.PLATFORM to version 10.0.1 or higher.
What versions of DNN.PLATFORM are affected by CVE-2025-52488?
CVE-2025-52488 affects DNN.PLATFORM versions from 6.0.0 to 10.0.0.
Can CVE-2025-52488 allow unauthorized access?
Yes, CVE-2025-52488 can allow an attacker to gain unauthorized access by exposing NTLM hashes.
Is a patch available for CVE-2025-52488?
Yes, a patch is available by upgrading to DNN.PLATFORM version 10.0.1.