← All articles Threat Intelligence

CVE-2025-65104: Windows LNK NTLM Hash Leak via Explorer Preview

By Ammar Khan, CEH · October 6, 2026 · CybernytronX Research
CVE-2025-65104: Windows LNK NTLM Hash Leak via Explorer Preview

In November 2025, Microsoft published advisory CVE-2025-65104, a forced-authentication flaw in Windows Explorer's preview pane: a crafted .lnk file causes the shell to initiate an outbound SMB connection to an attacker-controlled UNC path the moment the file is merely selected — no double-click, no execution, no macro prompt. The victim's NTLMv2 response is transmitted to the attacker, who can relay or crack it. This article breaks down the flaw mechanics, affected builds, real ATT&CK mappings, a working Sigma rule, and the registry and firewall mitigations Microsoft and CISA recommend.

Background: what CVE-2025-65104 actually is

CVE-2025-65104 is a forced-authentication (a.k.a. "hash leak") vulnerability in the Windows Shell — specifically in the code path that renders shortcut file metadata inside Explorer's preview pane and Details pane. Microsoft's advisory rates it Important with a CVSS v3.1 base score of 6.5 (NVD entry), and the CWE classification is CWE-294 (Authentication Bypass by Capture-replay) with a secondary CWE-522 (Insufficiently Protected Credentials).

The mechanics are not new in kind — this is the same family as the 2009-era .library-ms and .searchconnector-ms leaks, and the 2017 SearchConnector disclosure. What makes CVE-2025-65104 notable is that Microsoft shipped a code fix rather than only documentation, because the preview handler was resolving an icon location from the .lnk binary header (the IconLocation field of the LinkInfo structure) before checking whether the target was a local path. When the field contains a UNC path such as \\attacker.example\share\icon.ico, the shell's icon-resolution routine calls CoInitializeSecurity-negotiated SMB and offers NTLM authentication.

Per Microsoft's advisory, exploitation requires the user to "preview or select" the file — but Windows Explorer's default single-click preview behavior means no double-click is needed, and the leak fires even with file execution blocked by WDAC or AppLocker.

Affected versions and patch status

According to the Microsoft Security Update Guide entry for CVE-2025-65104, the vulnerability affects the Windows Shell across supported client and server SKUs. The November 2025 Patch Tuesday bundle addresses it in the following builds:

Verify the installed OS build with winver or Get-ComputerInfo | Select OsBuildNumber and compare against the KB article listed in the MSRC entry. Microsoft has not published a workaround-only path; the fix is a code change in shell32.dll and windows.storage.dll. No known public exploit code was attached at the original disclosure, but the technique is trivially reproducible from documented .lnk format specifications, and CISA added the vulnerability to the Known Exploited Vulnerabilities catalog after observed in-the-wild abuse in targeted phishing campaigns.

Attacker TTPs: how the leak is weaponized

The exploit primitive is small but the kill chain around it is well-trodden. The typical sequence maps cleanly to MITRE ATT&CK:

The critical operational detail: because the leak fires from the preview handler, endpoint protection that only blocks execution of .lnk files (a common AppLocker rule) does not stop it. The SMB client does the talking, and it is a Microsoft-signed binary making the outbound request.

Detection: Sigma, YARA, and network rules

Detection has three layers. First, catch the SMB egress to non-corporate file servers. Second, catch the .lnk artifact on disk or in email. Third, correlate the two.

Sigma — outbound SMB from Explorer to a non-RFC1918 host

title: Suspicious Outbound SMB from Explorer Preview Handler (CVE-2025-65104)
id: 8b1f7c2a-4d3e-4a21-9c8e-2f6a1b7d5e90
status: experimental
description: Detects explorer.exe initiating SMB (445/139) to a public IP,
  consistent with NTLM forced-auth via malicious .lnk preview.
references:
  - https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-65104
  - https://nvd.nist.gov/vuln/detail/CVE-2025-65104
author: CybernytronX
date: 2025/11/20
logsource:
  category: network_connection
  product: windows
detection:
  selection_img:
    Image|endswith: '\explorer.exe'
  selection_port:
    DestinationPort:
      - 445
      - 139
  filter_private:
    DestinationIp|cidr:
      - '10.0.0.0/8'
      - '172.16.0.0/12'
      - '192.168.0.0/16'
      - '127.0.0.0/8'
  condition: selection_img and selection_port and not filter_private
falsepositives:
  - Legitimate DFS or branch-office file servers on public IP space
level: medium
tags:
  - attack.t1557.001
  - attack.t1187
  - cve.2025.65104

YARA — malicious .lnk embedding a UNC IconLocation

rule lnk_unc_iconlocation_cve_2025_65104
{
    meta:
        author = "CybernytronX"
        description = "Detects .lnk files whose IconLocation points to a UNC path"
        reference = "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-65104"
        date = "2025-11-20"
    strings:
        $magic = { 4C 00 00 00 01 14 02 00 00 00 00 00 C0 00 00 00 00 00 00 46 }
        $unc   = "\\\\" ascii wide nocase
    condition:
        $magic at 0 and $unc
}

Suricata — SMB2 negotiate with NTLMSSP from a workstation

alert smb any any -> any 445 ( \
  msg:"SMB2 NTLMSSP negotiate from workstation - possible CVE-2025-65104 leak"; \
  flow:to_server,established; \
  content:"|fe 53 4d 42|"; depth:4; \
  content:"NTLMSSP"; nocase; \
  threshold:type limit, track by_src, count 1, seconds 300; \
  classtype:attempted-recon; sid:202565104; rev:1; )

On the telemetry side, hunt for Event ID 4624 Logon Type 3 with AuthenticationPackageName=NTLM originating from a workstation account and a source IP that is not a domain controller or file server. Sysmon Event ID 3 with Image=explorer.exe and DestinationPort=445 is the highest-signal single event.

Mitigation: what actually stops the leak

Microsoft's fix is the code change in the November 2025 cumulative updates. Until those are deployed fleet-wide, and as defense-in-depth afterward, these controls materially reduce blast radius:

Microsoft's KB article for each affected build lists the exact build number required; verify with Get-HotFix | Where-Object HotFixID -eq 'KB5068861' on Windows 11 24H2.

Why this matters for defenders

CVE-2025-65104 is a reminder that the Windows Shell is an attack surface whose trust model predates the modern enterprise. Preview handlers were designed to make file browsing pleasant on a single-user workstation with a trusted LAN; they were never designed for a laptop on hotel Wi-Fi opening a file from a recruiter. The fix Microsoft shipped is narrow — it validates the icon path — but the class of bug recurs because the underlying pattern (resolve a user-supplied network path, offer ambient credentials) is baked into dozens of shell extensions, Office features, and third-party previewers.

For a CISO, the practical takeaway is that blocking execution is not blocking exploitation. If your endpoint control strategy assumes that a file the user did not double-click cannot hurt them, CVE-2025-65104 falsifies that assumption. The controls that actually work are network-level: outbound SMB restrictions, NTLM outbound denial, SMB signing, and EPA. Those controls also neutralize the next forced-auth bug, whatever its CVE number turns out to be. Patch this month, but treat the outbound SMB rule as the durable fix.

Sources

Frequently Asked Questions

Does the user have to open the .lnk file for CVE-2025-65104 to trigger?

No. The leak fires when the file is selected in Explorer with the preview pane enabled, because the shell resolves the icon location before any user-initiated open. Disabling the preview pane via the ShowPreviewHandlers registry value removes the trigger.

Can AppLocker or WDAC blocking .lnk execution stop this?

No. The outbound SMB request is made by explorer.exe, a Microsoft-signed binary that is always allowed. Execution-control policies do not intercept the credential offer. Network-level controls — outbound SMB firewall rules and NTLM outbound restrictions — are required.

Is the leaked hash immediately usable, or does it need cracking?

Both paths are viable. NTLMv2 responses can be relayed in real time to a host that accepts NTLM (SMB without signing, LDAP without signing, or AD CS Web Enrollment) or cracked offline with hashcat mode 5600. Enforcing SMB signing and EPA closes the relay path; long, unique machine passwords raise the cracking cost.

Which Windows builds are affected?

Per the Microsoft advisory, Windows 10 22H2, Windows 11 23H2 and 24H2, Windows Server 2022, and Windows Server 2025 are affected. The November 2025 cumulative updates (for example KB5068861 on 24H2) contain the fix. Verify with winver against the KB listed in the MSRC entry.

Does this affect Windows Server or only workstations?

The vulnerable shell code ships on both, but exploitation requires an interactive user browsing a folder with the preview pane enabled. Server Core has no Explorer shell and is not exposed. RDS and VDI session hosts are exposed and should be treated as high priority.

What is the fastest compensating control if patching is delayed?

Push a GPO firewall rule denying outbound TCP 445 and 139 to any destination outside your RFC1918 ranges. This blocks the NTLM offer from leaving the host and neutralizes CVE-2025-65104 and the broader forced-authentication class in one change.

Need expert help with this?

CybernytronX helps security teams close forced-authentication gaps like CVE-2025-65104 with targeted internal penetration testing, NTLM and SMB hardening reviews, and SOC detection engineering. Our Ethereon AI threat-detection platform correlates the outbound SMB and NTLM telemetry described above so leaks surface in minutes, not quarters. If your patching window is tight or your preview-pane policy is unclear, talk to us at cybernytronx.com/contact.html or explore Ethereon.

AK

Ammar Khan — Founder, CybernytronX

Certified Ethical Hacker (CEH), B.S. Cybersecurity, Google Certified. 5+ years pentesting, creator of Ethereon AI threat detection. Has remediated 50+ environments and recovered 20+ compromised domains. Hire CybernytronX →

← Back to all articles