
Researchers from 0patch have discovered a critical zero-day vulnerability in Windows, affecting multiple versions of the operating system. This vulnerability exposes users to credential theft through the theft of NTLM credentials via a simple yet deceptive method. The vulnerability affects all Windows versions from Windows 7 and Server 2008 R2 up to the latest Windows 11 24H2 and Server 2022.
Attackers can exploit this flaw by tricking users into viewing a malicious file in Windows Explorer. This can be done by opening a shared folder, connecting a USB disk that contains the malicious file, or even accessing the Downloads folder where the file may have been automatically downloaded from an attacker’s webpage.
When the malicious file is viewed, it triggers the theft of NTLM credentials, which can then be used by attackers for unauthorized access. The researchers at 0patch have responsibly reported the issue to Microsoft and have also released an unofficial micropatch to protect users until an official fix is provided. To minimize the risk of exploitation, the researchers have withheld detailed technical information about the vulnerability.
This discovery highlights the importance of staying vigilant and applying security updates promptly. It also emphasizes the need for Microsoft to prioritize releasing an official patch for this vulnerability to ensure users are protected.

