← back
CVE-2025-24991

Windows NTFS Information Disclosure Vulnerability

CVSS 5.5 MEDIUMEPSS 1.9%● KEVCWE-125
In short

A flaw in Windows NTFS allows someone with local access to read data beyond the intended boundaries of a file system structure, potentially exposing sensitive information stored on the system.

Technical detail

An out-of-bounds read vulnerability in the NTFS driver permits authenticated local attackers to access memory regions outside legitimate file system metadata boundaries, enabling information disclosure. The attack requires prior system access and results in unauthorized exposure of sensitive kernel or file system data.

Summary generated and translated by AI from the official description.
Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally.
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N/E:F/RL:O/RC:C

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →