← back
CVE-2025-21197mediumCWE-284

Windows NTFS Information Disclosure Vulnerability

13Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 6.5epss 3.2%
exploitation probability
3.2%top 12% of all CVEs
observed exploitation
nono source reports it
Improper access control in Windows NTFS allows an authorized attacker to disclose file path information under a folder where the attacker doesn't have permission to list content.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C