Colombian security researcher Juan Diego recently discovered that a threat actor could easily obtain NT LAN Manager (NTLM) password hashes without any user intervention. The attack is automatic: A Shell Command File (SCF) is placed in a public folder with no password protection. It then sucks up the NTLM password hash and sends it to the attackers server. This is a long-standing architectural flaw in Windows that Microsoft has been reluctant to discuss or fix. Microsoft has not announced any plans to extend the patch to previous versions of Windows 10 and Windows Server 2016.”]
Source: https://securityintelligence.com/news/windows-vulnerability-puts-ntlm-password-hashes-at-risk/