Critical Vulnerabilities in Internet Shortcut and NTLM Expose Networks to Attacks
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Two critical vulnerabilities have been identified: CVE-2025-33053 in Internet Shortcut Files and CVE-2025-24054 in Windows NTLM. Both vulnerabilities allow unauthorized attackers to execute code or perform spoofing over a network. The vulnerabilities are linked to external control of file names or paths, making them particularly dangerous. Organizations using affected systems are at risk of exploitation, which could lead to significant data breaches or unauthorized access. CISA has referenced these vulnerabilities in its BOD 22-01 advisory, urging immediate attention. No specific patches or remediation steps were detailed in the articles. The vulnerabilities affect a wide range of software that utilizes these file types. Security teams are advised to consult the Known Exploited Vulnerabilities Catalog for further guidance.
Key Points: • CVE-2025-33053 allows code execution via Internet Shortcut Files. • CVE-2025-24054 enables spoofing through Windows NTLM vulnerabilities. • CISA has issued advisories urging immediate action on these vulnerabilities.