A significant security vulnerability has been discovered in Windows operating systems due to the use of the outdated NTLM password hashing method. This vulnerability affects all Windows client versions starting from Windows 7, leaving a large number of users at risk. Exploiting the vulnerability does not require special privileges, allowing a wide range of attackers to capture NTLM authentication hashes, which can lead to further security breaches. The vulnerability can be triggered easily by viewing a malicious theme file in Windows Explorer, and users may unknowingly activate it through automatic downloads.