Git for Windows leaks NTLM hash when cloning from an attacker-controlled server
Vulnerability Description
Git for Windows is the Windows port of Git. Prior to 2.53.0(2), it is possible to obtain a user's NTLM hash by tricking them into cloning from a malicious server. Since NTLM hashing is weak, it is possible for the attacker to brute-force the user's account name and password. This vulnerability is fixed in 2.53.0(2).
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-66413
Credits & Attribution
No credits recorded in the NVD database.
References
More from git-for-windows
View All →Affected Vendor
git-for-windows
View all reports →