CVE-2025-24984
KEVmassInformation Disclosure in Windows NTFS Log Files via Physical Attack
CISA: Microsoft Windows NTFS Information Disclosure Vulnerability
CVE-2025-24984 is an information disclosure flaw in Microsoft Windows NTFS caused by sensitive information being inserted into log files (CWE-532). Exploitation requires a physical attack: an unauthorized attacker with physical access to a machine can obtain sensitive information that NTFS has written into its log files; the attack requires no privileges or user interaction and impacts confidentiality only (CVSS 4.6, AV:P). Affected products span all listed Windows 10 versions (1507, 1607, 1809, 21H2, 22H2), Windows 11 22H2/23H2/24H2, and Windows Server 2012, 2016, 2019, and 2022. Microsoft fixed the flaw in its March 2025 Patch Tuesday release, and CISA added it to the Known Exploited Vulnerabilities catalog on 2025-03-11 as one of six actively exploited Windows zero-days; no public proof-of-concept is known and ransomware use is unknown. EPSS currently assigns a 2.0% probability of exploitation in the next 30 days (79th percentile).
What to do: Apply Microsoft's March 2025 security updates (released March 11, 2025) to all affected Windows 10, Windows 11, and Windows Server systems, and confirm the March cumulative update is installed on your builds; organizations subject to CISA BOD 22-01 must act within the KEV deadline. Because exploitation requires physical access, prioritize patching and restrict physical access to laptops, kiosks, and other physically reachable systems while updates roll out.
| Microsoft Windows 10 | 1507, 1607, 1809, 21H2, 22H2 |
| Microsoft Windows 11 | 22H2, 23H2, 24H2 |
| Microsoft Windows Server | 2012, 2016, 2019, 2022 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Insertion of sensitive information into log file in Windows NTFS allows an unauthorized attacker to disclose information with a physical attack.
- Affected
- Microsoft Windows
- Required action
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- microsoft
- Products
- windows 10 1507, windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 22h2, windows 11 23h2, windows 11 24h2, windows server 2012, windows server 2016, windows server 2019, windows server 2022
- Weakness
- CWE-532
- Vector
- CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N