In November 2025, Microsoft published advisory CVE-2025-65104, a forced-authentication flaw in Windows Explorer's preview pane: a crafted .lnk file causes the shell to initiate an outbound SMB connection to an attacker-controlled UNC path the moment the file is merely selected — no double-click, no execution, no macro prompt. The victim's NTLMv2 response is transmitted to the attacker, who can relay or crack it. This article breaks down the flaw mechanics, affected builds, real ATT&CK mappings, a working Sigma rule, and the registry and firewall mitigations Microsoft and CISA recommend.
Background: what CVE-2025-65104 actually is
CVE-2025-65104 is a forced-authentication (a.k.a. "hash leak") vulnerability in the Windows Shell — specifically in the code path that renders shortcut file metadata inside Explorer's preview pane and Details pane. Microsoft's advisory rates it Important with a CVSS v3.1 base score of 6.5 (NVD entry), and the CWE classification is CWE-294 (Authentication Bypass by Capture-replay) with a secondary CWE-522 (Insufficiently Protected Credentials).
The mechanics are not new in kind — this is the same family as the 2009-era .library-ms and .searchconnector-ms leaks, and the 2017 SearchConnector disclosure. What makes CVE-2025-65104 notable is that Microsoft shipped a code fix rather than only documentation, because the preview handler was resolving an icon location from the .lnk binary header (the IconLocation field of the LinkInfo structure) before checking whether the target was a local path. When the field contains a UNC path such as \\attacker.example\share\icon.ico, the shell's icon-resolution routine calls CoInitializeSecurity-negotiated SMB and offers NTLM authentication.
Per Microsoft's advisory, exploitation requires the user to "preview or select" the file — but Windows Explorer's default single-click preview behavior means no double-click is needed, and the leak fires even with file execution blocked by WDAC or AppLocker.
Affected versions and patch status
According to the Microsoft Security Update Guide entry for CVE-2025-65104, the vulnerability affects the Windows Shell across supported client and server SKUs. The November 2025 Patch Tuesday bundle addresses it in the following builds:
- Windows 11 24H2 — KB5068861 (OS Build 26100.4xxx and later)
- Windows 11 23H2 — KB5068863 (OS Build 22631.5xxx and later)
- Windows 10 22H2 — KB5068781 (OS Build 19045.6xxx and later), including ESU customers
- Windows Server 2022 — KB5068791
- Windows Server 2025 — KB5068861 (shared servicing branch with 24H2)
Verify the installed OS build with winver or Get-ComputerInfo | Select OsBuildNumber and compare against the KB article listed in the MSRC entry. Microsoft has not published a workaround-only path; the fix is a code change in shell32.dll and windows.storage.dll. No known public exploit code was attached at the original disclosure, but the technique is trivially reproducible from documented .lnk format specifications, and CISA added the vulnerability to the Known Exploited Vulnerabilities catalog after observed in-the-wild abuse in targeted phishing campaigns.
Attacker TTPs: how the leak is weaponized
The exploit primitive is small but the kill chain around it is well-trodden. The typical sequence maps cleanly to MITRE ATT&CK:
- T1566.001 — Phishing: Spearphishing Attachment. A ZIP containing a single
.lnkis delivered via email or a chat platform. The.lnkhas a benign-looking icon and a target pointing to\\.\share\payload - T1036.005 — Masquerading: Match Legitimate Name or Location. The filename mimics an invoice, résumé, or scanned document; the icon is copied from a legitimate Office document.
- T1187 — Drive-by Compromise (adjacent). When the file lands in a folder the user browses, Explorer's preview pane triggers the outbound SMB request without user action beyond selection.
- T1557.001 — Adversary-in-the-Middle: LLMNR/NBT-NS Poisoning and SMB Relay. The attacker either captures the NTLMv2 response for offline cracking (hashcat mode 5600) or relays it to a second host using
ntlmrelayx.pyfrom Impacket. - T1078 — Valid Accounts. A relayed NTLM authentication against SMB on a target host can yield a session, and against AD CS with the Web Enrollment role can yield a certificate — the ESC8 path.
The critical operational detail: because the leak fires from the preview handler, endpoint protection that only blocks execution of .lnk files (a common AppLocker rule) does not stop it. The SMB client does the talking, and it is a Microsoft-signed binary making the outbound request.
Detection: Sigma, YARA, and network rules
Detection has three layers. First, catch the SMB egress to non-corporate file servers. Second, catch the .lnk artifact on disk or in email. Third, correlate the two.
Sigma — outbound SMB from Explorer to a non-RFC1918 host
title: Suspicious Outbound SMB from Explorer Preview Handler (CVE-2025-65104)
id: 8b1f7c2a-4d3e-4a21-9c8e-2f6a1b7d5e90
status: experimental
description: Detects explorer.exe initiating SMB (445/139) to a public IP,
consistent with NTLM forced-auth via malicious .lnk preview.
references:
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-65104
- https://nvd.nist.gov/vuln/detail/CVE-2025-65104
author: CybernytronX
date: 2025/11/20
logsource:
category: network_connection
product: windows
detection:
selection_img:
Image|endswith: '\explorer.exe'
selection_port:
DestinationPort:
- 445
- 139
filter_private:
DestinationIp|cidr:
- '10.0.0.0/8'
- '172.16.0.0/12'
- '192.168.0.0/16'
- '127.0.0.0/8'
condition: selection_img and selection_port and not filter_private
falsepositives:
- Legitimate DFS or branch-office file servers on public IP space
level: medium
tags:
- attack.t1557.001
- attack.t1187
- cve.2025.65104
YARA — malicious .lnk embedding a UNC IconLocation
rule lnk_unc_iconlocation_cve_2025_65104
{
meta:
author = "CybernytronX"
description = "Detects .lnk files whose IconLocation points to a UNC path"
reference = "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-65104"
date = "2025-11-20"
strings:
$magic = { 4C 00 00 00 01 14 02 00 00 00 00 00 C0 00 00 00 00 00 00 46 }
$unc = "\\\\" ascii wide nocase
condition:
$magic at 0 and $unc
}
Suricata — SMB2 negotiate with NTLMSSP from a workstation
alert smb any any -> any 445 ( \
msg:"SMB2 NTLMSSP negotiate from workstation - possible CVE-2025-65104 leak"; \
flow:to_server,established; \
content:"|fe 53 4d 42|"; depth:4; \
content:"NTLMSSP"; nocase; \
threshold:type limit, track by_src, count 1, seconds 300; \
classtype:attempted-recon; sid:202565104; rev:1; )
On the telemetry side, hunt for Event ID 4624 Logon Type 3 with AuthenticationPackageName=NTLM originating from a workstation account and a source IP that is not a domain controller or file server. Sysmon Event ID 3 with Image=explorer.exe and DestinationPort=445 is the highest-signal single event.
Mitigation: what actually stops the leak
Microsoft's fix is the code change in the November 2025 cumulative updates. Until those are deployed fleet-wide, and as defense-in-depth afterward, these controls materially reduce blast radius:
- Disable the preview pane via policy. Set
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ShowPreviewHandlers = 0and push it via Group Policy Preferences. This removes the trigger for the vulnerable code path. - Block outbound SMB at the host firewall. A GPO firewall rule denying TCP 445 and 139 to non-RFC1918 destinations prevents the NTLM offer from ever leaving the subnet. This is the single highest-value control for the entire forced-authentication class.
- Disable NTLM outbound where possible. Microsoft's Network security: Restrict NTLM: Outgoing NTLM traffic to remote servers policy can be set to Deny all in environments already running Kerberos-only authentication.
- Enable SMB signing and EPA. SMB signing (required on all hosts via GPO) and Extended Protection for Authentication on AD CS Web Enrollment break the relay leg of the attack even when the hash leaks.
- Strip .lnk from inbound email and archive attachments. Most secure email gateways can block the extension, though this is bypassable via container formats — treat it as a speed bump, not a control.
Microsoft's KB article for each affected build lists the exact build number required; verify with Get-HotFix | Where-Object HotFixID -eq 'KB5068861' on Windows 11 24H2.
Why this matters for defenders
CVE-2025-65104 is a reminder that the Windows Shell is an attack surface whose trust model predates the modern enterprise. Preview handlers were designed to make file browsing pleasant on a single-user workstation with a trusted LAN; they were never designed for a laptop on hotel Wi-Fi opening a file from a recruiter. The fix Microsoft shipped is narrow — it validates the icon path — but the class of bug recurs because the underlying pattern (resolve a user-supplied network path, offer ambient credentials) is baked into dozens of shell extensions, Office features, and third-party previewers.
For a CISO, the practical takeaway is that blocking execution is not blocking exploitation. If your endpoint control strategy assumes that a file the user did not double-click cannot hurt them, CVE-2025-65104 falsifies that assumption. The controls that actually work are network-level: outbound SMB restrictions, NTLM outbound denial, SMB signing, and EPA. Those controls also neutralize the next forced-auth bug, whatever its CVE number turns out to be. Patch this month, but treat the outbound SMB rule as the durable fix.
Sources
- Microsoft Security Update Guide — CVE-2025-65104 — authoritative affected-version list, CVSS score, and KB numbers for the November 2025 fix.
- NVD — CVE-2025-65104 — CWE classification (CWE-294, CWE-522) and CVSS vector.
- CISA Known Exploited Vulnerabilities Catalog — confirms in-the-wild exploitation and BOD 22-01 remediation timelines for federal agencies.
- Microsoft Learn — Restrict NTLM: Outgoing NTLM traffic to remote servers — documents the GPO that blocks the outbound NTLM offer at the source.
- MITRE ATT&CK T1557.001 — LLMNR/NBT-NS Poisoning and SMB Relay — technique context for the relay leg of the attack.
Frequently Asked Questions
Does the user have to open the .lnk file for CVE-2025-65104 to trigger?
No. The leak fires when the file is selected in Explorer with the preview pane enabled, because the shell resolves the icon location before any user-initiated open. Disabling the preview pane via the ShowPreviewHandlers registry value removes the trigger.
Can AppLocker or WDAC blocking .lnk execution stop this?
No. The outbound SMB request is made by explorer.exe, a Microsoft-signed binary that is always allowed. Execution-control policies do not intercept the credential offer. Network-level controls — outbound SMB firewall rules and NTLM outbound restrictions — are required.
Is the leaked hash immediately usable, or does it need cracking?
Both paths are viable. NTLMv2 responses can be relayed in real time to a host that accepts NTLM (SMB without signing, LDAP without signing, or AD CS Web Enrollment) or cracked offline with hashcat mode 5600. Enforcing SMB signing and EPA closes the relay path; long, unique machine passwords raise the cracking cost.
Which Windows builds are affected?
Per the Microsoft advisory, Windows 10 22H2, Windows 11 23H2 and 24H2, Windows Server 2022, and Windows Server 2025 are affected. The November 2025 cumulative updates (for example KB5068861 on 24H2) contain the fix. Verify with winver against the KB listed in the MSRC entry.
Does this affect Windows Server or only workstations?
The vulnerable shell code ships on both, but exploitation requires an interactive user browsing a folder with the preview pane enabled. Server Core has no Explorer shell and is not exposed. RDS and VDI session hosts are exposed and should be treated as high priority.
What is the fastest compensating control if patching is delayed?
Push a GPO firewall rule denying outbound TCP 445 and 139 to any destination outside your RFC1918 ranges. This blocks the NTLM offer from leaving the host and neutralizes CVE-2025-65104 and the broader forced-authentication class in one change.
Need expert help with this?
CybernytronX helps security teams close forced-authentication gaps like CVE-2025-65104 with targeted internal penetration testing, NTLM and SMB hardening reviews, and SOC detection engineering. Our Ethereon AI threat-detection platform correlates the outbound SMB and NTLM telemetry described above so leaks surface in minutes, not quarters. If your patching window is tight or your preview-pane policy is unclear, talk to us at cybernytronx.com/contact.html or explore Ethereon.