POC CVE-2025-24071
by caca28sapo1 - Thursday April 10, 2025 at 07:51 PM
#1
Windows Explorer automatically initiates an SMB authentication request when a .library-ms file is extracted from a .rar archive, leading to NTLM hash disclosure. The user does not need to open or execute the file—simply extracting it is enough to trigger the leak.

usage:

>>python poc.py

>>enter file name: your file name

>>enter IP: attacker IP

Link:
Hidden Content
You must register or login to view this content.
Reply
#2
Thanks, this worked for me
Reply
#3
nice mind blowing content from u brother
Reply
#4
Thanks, will give this a try!
If I end up writing anything myself I will create a new thread and credit you.
Reply
#5
Thank you! I will give it a try
Reply
#6
Thanks for sharing, not seen this one before
Reply
#7
Thank you for poc
This forum account is currently banned. Ban Length: (Permanent)
Ban Reason: Leeching | https://pwnforums.st/Forum-Ban-Appeals if you feel this is incorrect.
Reply
#8
Thanks for sharing, lemme check
Reply
#9
Thank you very much. I really need this.
Reply
#10
I don’t know abt that
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  new wordpress website takeover vuln (video + poc ) zinzeur 313 27,277 03-28-2026, 02:43 AM
Last Post: toshi99
  [POC] Google OAuth "MultiLogin" endpoint 0-day Farfallaiero 106 13,201 02-10-2026, 03:34 PM
Last Post: birhikayemvar
  Cool Remote Patching ETW/Amsi PoC pepeloco 6 2,092 02-08-2026, 07:58 AM
Last Post: zeroday99
  CVE-2025-40554 - SolarWinds Web Help Desk Auth Bypass & RCE PoC miyako 3 73 02-07-2026, 03:32 PM
Last Post: cysc
  HPE OneView RCE Exploit [CVE-2025-37164] Hawx01 8 261 02-06-2026, 07:08 PM
Last Post: hacker0123



 Users browsing this thread: