Critical Vulnerabilities in Internet Shortcut and NTLM Expose Networks to Attacks
Article Content
- •CVE-2025-33053 allows code execution via Internet Shortcut Files.
- •CVE-2025-24054 enables spoofing through Windows NTLM vulnerabilities.
- •CISA has issued advisories urging immediate action on these vulnerabilities.
Two critical vulnerabilities have been identified: CVE-2025-33053 in Internet Shortcut Files and CVE-2025-24054 in Windows NTLM. Both vulnerabilities allow unauthorized attackers to execute code or perform spoofing over a network. The vulnerabilities are linked to external control of file names or paths, making them particularly dangerous. Organizations using affected systems are at risk of exploitation, which could lead to significant data breaches or unauthorized access. CISA has referenced these vulnerabilities in its BOD 22-01 advisory, urging immediate attention. No specific patches or remediation steps were detailed in the articles. The vulnerabilities affect a wide range of software that utilizes these file types. Security teams are advised to consult the Known Exploited Vulnerabilities Catalog for further guidance.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Continue Reading
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…
Critical Linux Kernel Vulnerability CVE-2025-39682 Under Active Exploitation A critical vulnerability (CVE-2025-39682) in the Linux kernel allows remote code execution through mishandling of zero-length TLS records. This flaw affects kTLS-enabled hosts running vulnerable kernel versions, exposing them to attackers without authentication. CISA added this vulnerability to its Known Exploited…