Junglewise Threat Intelligence

CVE-2025-24991: Microsoft Windows NTFS Out-Of-Bounds Read Vulnerability

CVE-2025-24991 · Severity: critical · CVSS 5.5 · Exploited in the wild · Published 2025-03-11

Technologies: Microsoft Windows Server 2008, Microsoft Windows Server 2025, Microsoft Windows 10, Microsoft Windows, Microsoft Windows Server 2016, Microsoft Windows Server 2022 23h2, Microsoft Windows Server 2019, Microsoft Windows Server 2012. Vendors: Microsoft.

Executive brief

Microsoft Windows NTFS contains an out-of-bounds read vulnerability that allows an authorized attacker to disclose information locally. The flaw exists within the New Technology File System (NTFS) and requires user interaction to exploit.

Affected products

  • Microsoft Windows 10 up to (excluding) 10.0.10240.20947, 10.0.14393.7876, 10.0.17763.7009, 10.0.19044.5608, 10.0.19045.5608
  • Microsoft Windows Server 2008 SP2, R2 SP1
  • Microsoft Windows Server 2012 R2
  • Microsoft Windows Server 2016 up to (excluding) 10.0.14393.7876
  • Microsoft Windows Server 2019 up to (excluding) 10.0.17763.7009
  • Microsoft Windows Server 2022 23H2 up to (excluding) 10.0.25398.1486
  • Microsoft Windows Server 2025 up to (excluding) 10.0.26100.3403

Timeline

  • 2025-03-11: disclosed
  • 2025-03-11: advisory
  • 2025-03-11: kev added: Added to CISA KEV catalog
  • 2025-03-11: exploited: Reported as exploited in the wild at time of publication.

Related threats