Junglewise Threat Intelligence

CVE-2025-24993: Microsoft Windows NTFS Heap-Based Buffer Overflow Vulnerability

CVE-2025-24993 · Severity: critical · CVSS 7.8 · Exploited in the wild · Published 2025-03-11

Technologies: Microsoft Windows, Microsoft Windows Server, Microsoft Windows 10. Vendors: Microsoft.

Executive brief

A heap-based buffer overflow vulnerability in the Microsoft Windows New Technology File System (NTFS) allows an unauthorized attacker to execute code locally. The vulnerability requires user interaction and is currently known to be exploited in the wild.

Affected products

  • Microsoft Windows 10 1507, 1607, 1809, 21H2, 22H2
  • Microsoft Windows Server 2008, 2012, 2016, 2019, 2022, 2025

Timeline

  • 2025-03-11: disclosed
  • 2025-03-11: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2025-03-11: advisory: Microsoft published vendor advisory

Related threats