ZeroHour

CVE-2025-24991

KEVmass

Out-of-Bounds Read in Microsoft Windows NTFS Enables Local Information Disclosure

CISA: Microsoft Windows NTFS Out-Of-Bounds Read Vulnerability

CVSS 3.1
5.5 medium
EPSS
2%p79
Published
()
KEV added
AI analysis

CVE-2025-24991 is an out-of-bounds read vulnerability (CWE-125) in the Windows NTFS component, allowing a local, authorized attacker to read beyond allocated buffer boundaries. The flaw is triggered in a local attack scenario (AV:L) with user interaction required (UI:R), per the CVSS 3.1 vector. A successful exploit discloses sensitive information from affected memory (high confidentiality impact), with no integrity or availability impact and no privilege escalation or remote code execution. Affected systems span a broad set of supported releases: Windows 10 (1507, 1607, 1809, 21H2, 22H2), Windows 11 (22H2, 23H2, 24H2), and Windows Server 2008, 2012, 2016, and 2019. The vulnerability is actively exploited in the wild — CISA added it to the Known Exploited Vulnerabilities catalog on 2025-03-11 as one of six Microsoft Windows flaws added that week, and Microsoft addressed it in the March 2025 Patch Tuesday release of 57 fixes, including six actively exploited zero-days; EPSS currently estimates a 2.0% probability of exploitation in the next 30 days.

What to do: Apply Microsoft's March 2025 Patch Tuesday security updates to all affected Windows 10/11 client and Windows Server 2008/2012/2016/2019 systems, prioritizing internet-relevant and multi-user hosts given confirmed in-the-wild exploitation. Federal agencies must remediate per CISA KEV/BOD 22-01 timelines or remove the product from service if mitigations are unavailable. Because the flaw is exploitable by a local authorized user, review which local or low-privilege accounts can access exposed Windows hosts while patching completes.

Affected
microsoft Windows 101507
microsoft Windows 101607
microsoft Windows 101809
microsoft Windows 1021H2
microsoft Windows 1022H2
microsoft Windows 1122H2
microsoft Windows 1123H2
microsoft Windows 1124H2
microsoft Windows Server 2008as listed in CPE (Windows Server 2008)
microsoft Windows Server 2012as listed in CPE (Windows Server 2012)
microsoft Windows Server 2016as listed in CPE (Windows Server 2016)
microsoft Windows Server 2019as listed in CPE (Windows Server 2019)
Estimated exposure
masshundreds of millions of Windows client and server installations (Windows runs on 1.4B+ active devices; all supported Windows 10/11 releases and mainstream… — The affected CPE list covers essentially the entire supported Windows client and server installed base, and Microsoft has publicly reported more than 1.4 billion active Windows devices, so even conservative deployment-share assumptions put…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally.

CISA Known Exploited Vulnerability
Affected
Microsoft Windows
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
microsoft
Products
windows 10 1507, windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 22h2, windows 11 23h2, windows 11 24h2, windows server 2008, windows server 2012, windows server 2016, windows server 2019
Weakness
CWE-125
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

In the news