Executive brief
A vulnerability in the Microsoft Windows New Technology File System (NTFS) allows for the insertion of sensitive information into log files. An unauthorized attacker with physical access could exploit this to disclose portions of heap memory.
Affected products
- Microsoft Windows 10 1507, 1607, 1809, 21H2, 22H2
- Microsoft Windows 11 22H2, 23H2, 24H2
- Microsoft Windows Server 2012, 2012 R2, 2016, 2019, 2022, 2025, 23H2
Timeline
- 2025-03-11: disclosed
- 2025-03-11: patched
- 2025-03-11: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2025-03-11: exploited: Reported as exploited in the wild per CISA and advisory metadata.