CVE-2025-29745
7.5Emsisoft · Anti-Malware
A vulnerability in the Emsisoft Anti-Malware scanning module allows remote unauthenticated attackers to capture Net-NTLMv2 hash information via a malicious A2S extension file.
Executive summary
A critical vulnerability in Emsisoft Anti-Malware allows remote attackers to perform NTLM relay or cracking attacks by stealing Net-NTLMv2 hashes.
Vulnerability
The flaw resides in the scanning module, which improperly handles specially crafted A2S extension files. An unauthenticated attacker can trigger this behavior to force the application to leak Net-NTLMv2 hashes to a remote server.
Business impact
The capture of Net-NTLMv2 hashes poses a significant risk to organizational identity security. These hashes can be leveraged by attackers to perform NTLM relay attacks or offline brute-force cracking, potentially leading to unauthorized access to internal network resources and domain compromise. Given the CVSS score of 7.5, this vulnerability represents a high risk to environment integrity.
Remediation
Immediate Action: Update Emsisoft Anti-Malware to version 2024.12 or later immediately to resolve the vulnerable scanning logic.
Proactive Monitoring: Review network logs for unusual outbound SMB or HTTP traffic originating from endpoints running Emsisoft, specifically looking for connections to unknown external IP addresses.
Compensating Controls: Implement SMB signing or enforce NTLMv2 with Extended Protection for Authentication (EPA) to mitigate the impact of relayed hashes.
Exploitation status
Public Exploit Available: Yes — a published proof-of-concept exists as documented in the linked technical write-up from PacketStorm.
Analyst recommendation
This vulnerability presents a clear path for credential theft and lateral movement within the network. IT administrators should prioritize the deployment of the vendor-supplied update across all managed endpoints. Until patching is complete, ensure that network segmentation and robust authentication policies are in place to limit the potential success of NTLM relay attempts.