Executive brief
A heap-based buffer overflow vulnerability in the Microsoft Windows New Technology File System (NTFS) allows an unauthorized attacker to execute code locally. The vulnerability requires user interaction and is currently known to be exploited in the wild.
Affected products
- Microsoft Windows 10 1507, 1607, 1809, 21H2, 22H2
- Microsoft Windows Server 2008, 2012, 2016, 2019, 2022, 2025
Timeline
- 2025-03-11: disclosed
- 2025-03-11: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2025-03-11: advisory: Microsoft published vendor advisory