Summary
This security flaw is caused by an information disclosure weakness that enables unauthorised actors to access The vulnerability CVE-2024-38200 (CVSS score: 7.5) is an information disclosure vulnerability that allows remote attackers to access NTLM hashes. Attackers can exploit this flaw via a specially crafted file or web-based attack, potentially leading to NTLM relay attacks or password According to Microsoft’s advisory, the following products are affected [4]: 1. Set the “Restrict NTLM: Outgoing NTLM traffic to remote servers” group policy to block NTLM traffic from computers running Windows 7, Windows Server 2008, or later to any 2. Add users to the Protected Users Security Group, which restricts NTLM as an authentication method [3]. 3. Block all outbound traffic on TCP port 445 to prevent NTLM traffic from leaving the CERT-EU recommends applying the mitigations provided by Microsoft [4], including blocking outbound NTLM traffic, while Microsoft releases the updates.