ThreatCluster

New PoC Exploit for NTLM Reflection Bypass Vulnerability on Windows Server

First seen 30 Jun 2026, 13:59 UTC CybersecuritynewsGbhackers 93% similarity 72
Share:

Article Content

Browse articles
ThreatCluster

A proof-of-concept (PoC) exploit has been released for a NTLM reflection bypass vulnerability, tracked as CVE-2026-24294, which allows attackers to gain SYSTEM-level access on Windows Server 2025. This vulnerability arises from design flaws that were not fully addressed by the previous patch for CVE-2025-33073. The original mitigation only covered the SMB client path, leaving other vectors open for exploitation. The PoC was made public on April 30, 2026, and raises significant concerns about the effectiveness of Microsoft's authentication hardening measures. Organizations using Windows Server 2025 are at risk, particularly those that have not implemented additional security layers. The release of the PoC has prompted urgent advisories for system administrators to assess their environments and apply necessary mitigations.

Key Points: • CVE-2026-24294 allows SYSTEM access via NTLM reflection bypass on Windows Server 2025. • The vulnerability exploits unaddressed design flaws from the previous CVE-2025-33073 patch. • Immediate action is recommended for organizations to secure their Windows Server environments.

ThreatCluster AI

Timeline

2025-06-10
CVE-2025-33073 published
Microsoft disclosed an NTLM reflection vulnerability affecting Windows Server, leading to potential SYSTEM access.
Cybersecuritynews
2025-10-20
CVE-2025-33073 added to CISA KEV
CISA added the vulnerability to its Known Exploited Vulnerabilities catalog due to active exploitation.
Cybersecuritynews
2026-03-10
CVE-2026-24294 published
A new NTLM reflection bypass vulnerability was published, allowing SYSTEM-level access on Windows Server 2025.
Cybersecuritynews
2026-04-30
First public PoC for CVE-2026-24294
A working proof-of-concept exploit was released, demonstrating the vulnerability's potential for exploitation.
Gbhackers
2026-06-30
PoC exploit raises security concerns
The release of the PoC for CVE-2026-24294 has prompted urgent advisories for Windows Server 2025 users.
Cybersecuritynews

Community

Browse all →