Windows NTLM V1 Elevation of Privilege Vulnerability
The vulnerability is related to improper implementation of the NTLM authentication mechanism in version 1 (CWE-303 — error in the implementation of authentication protocol steps). An attacker can exploit the vulnerability remotely, without possessing any privileges and without user involvement, suggesting the possibility of conducting an attack directly on the NTLM network stack. The detailed technical mechanism has not been disclosed by the vendor.
Successful exploitation of the vulnerability allows an attacker to gain complete control over the system — obtaining confidential data, modifying data, and causing service unavailability (full impact on confidentiality, integrity, and availability).
Security updates published by Microsoft as part of the January 2025 Patch Tuesday should be applied immediately, available through Microsoft Update Catalog and WSUS. Additionally, it is recommended to consider disabling or restricting the use of NTLM V1 protocol in the environment according to Microsoft guidelines (Group Policy: 'Network security: LAN Manager authentication level').
Microsoft Windows 11 24H2, Microsoft Windows Server 2022 23H2, Microsoft Windows Server 2025
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HMicrosoft Windows 11 24h2
OSMicrosoft< 10.0.26100.2894Microsoft Windows Server 2022 23h2
OSMicrosoft< 10.0.25398.1369Microsoft Windows Server 2025
OSMicrosoft< 10.0.26100.2894
Related vulnerabilities
Double free w Windows IKE Extension umożliwia zdalne wykonanie kodu
RCE w Windows Server Update Service (WSUS) — deserializacja danych
Stack-based buffer overflow in Windows DNS allows an unauthorized attacker to execute code over a network.
Use after free in Microsoft QUIC allows an unauthorized attacker to execute code over a network.
Use after free in Windows Deployment Services allows an unauthorized attacker to execute code over a network.