Vulnerability record · CVE-2024-43451 · published 12 November 2024
CVE-2024-43451: Microsoft Windows NTLMv2 hash disclosure via spoofing
Microsoft · Windows 10 1507
CVE-2024-43451 is an NTLM hash disclosure spoofing vulnerability in Microsoft Windows. An attacker can induce a victim to disclose their NTLMv2 hash, which can then be relayed or cracked to gain access to other systems. It affects a broad range of Windows client and server versions and is listed in CISA's Known Exploited Vulnerabilities catalog.
Description
NTLM Hash Disclosure Spoofing Vulnerability
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Automated analysis
high priorityThe flaw is actively exploited per CISA KEV and has very high EPSS, but requires user interaction and only discloses credentials rather than granting direct code execution.
What it is
CVE-2024-43451 is an NTLM hash disclosure spoofing vulnerability in Microsoft Windows. An attacker can induce a victim to disclose their NTLMv2 hash, which can then be relayed or cracked to gain access to other systems. It affects a broad range of Windows client and server versions and is listed in CISA's Known Exploited Vulnerabilities catalog.
Impact
An attacker obtains the victim's NTLMv2 hash, enabling offline cracking or NTLM relay attacks that can lead to credential theft and lateral movement. The direct impact is confidentiality loss; integrity and availability are not affected per the CVSS vector.
Attack surface
The vulnerability is network-reachable (AV:N) with no privileges required (PR:N), but exploitation requires user interaction (UI:R), such as opening a crafted file or clicking a malicious link. No authentication is needed on the attacker's side.
Exploitation
CVE-2024-43451 is listed in CISA KEV with a due date of 2024-12-03, indicating known exploitation in the wild. EPSS gives a 30-day exploitation probability of 0.841 (99.7th percentile), and the record does not document ransomware group use.
What to do
- Apply the Microsoft security update referenced in the MSRC advisory for all affected Windows versions.
- Prioritize patching internet-facing and high-value systems, and meet the CISA KEV remediation deadline of 2024-12-03.
- Disable NTLM authentication where feasible and enforce SMB signing and LDAP signing/channel binding to block relay.
- Restrict outbound SMB and WebDAV traffic and block NTLM authentication to external hosts to limit hash capture.
- Enable Windows Defender Credential Guard and Protected Users to reduce credential exposure.
Detection
- Monitor for outbound NTLM authentication attempts to untrusted or external IP addresses and unusual SMB/WebDAV connections.
- Alert on NTLM authentication events (e.g., Event ID 4624 type 3) originating from workstations to unexpected servers.
- Hunt for processes opening files from untrusted locations (email attachments, downloads, removable media) that trigger outbound authentication.
- Correlate NTLM relay indicators such as duplicate or anomalous authentication attempts across hosts.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2024-43451 to the Known Exploited Vulnerabilities catalog on 12 November 2024 as "Microsoft Windows NTLMv2 Hash Disclosure Spoofing Vulnerability". Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 3 December 2024.
Affected products
15 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-43451 | PatchVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-43451 | US Government Resource |
Track CVE-2024-43451 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-43451), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.