Medium severity5.3NVD Advisory· Published Jun 24, 2024· Updated Jun 17, 2026
CVE-2024-33881
CVE-2024-33881
Description
An issue was discovered in VirtoSoftware Virto Bulk File Download 5.5.44 for SharePoint 2019. The Virto.SharePoint.FileDownloader/Api/Download.ashx isCompleted method allows an NTLMv2 hash leak via a UNC share pathname in the path parameter.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:a:virtosoftware:sharepoint_bulk_file_download:5.5.44:*:*:*:*:*:*:*
- VirtoSoftware/Virto Bulk File Download for SharePoint 2019description
- Range: <=5.5.44
Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.