CVE-2025-24991
KEVmassOut-of-Bounds Read in Microsoft Windows NTFS Enables Local Information Disclosure
CISA: Microsoft Windows NTFS Out-Of-Bounds Read Vulnerability
CVE-2025-24991 is an out-of-bounds read vulnerability (CWE-125) in the Windows NTFS component, allowing a local, authorized attacker to read beyond allocated buffer boundaries. The flaw is triggered in a local attack scenario (AV:L) with user interaction required (UI:R), per the CVSS 3.1 vector. A successful exploit discloses sensitive information from affected memory (high confidentiality impact), with no integrity or availability impact and no privilege escalation or remote code execution. Affected systems span a broad set of supported releases: Windows 10 (1507, 1607, 1809, 21H2, 22H2), Windows 11 (22H2, 23H2, 24H2), and Windows Server 2008, 2012, 2016, and 2019. The vulnerability is actively exploited in the wild — CISA added it to the Known Exploited Vulnerabilities catalog on 2025-03-11 as one of six Microsoft Windows flaws added that week, and Microsoft addressed it in the March 2025 Patch Tuesday release of 57 fixes, including six actively exploited zero-days; EPSS currently estimates a 2.0% probability of exploitation in the next 30 days.
What to do: Apply Microsoft's March 2025 Patch Tuesday security updates to all affected Windows 10/11 client and Windows Server 2008/2012/2016/2019 systems, prioritizing internet-relevant and multi-user hosts given confirmed in-the-wild exploitation. Federal agencies must remediate per CISA KEV/BOD 22-01 timelines or remove the product from service if mitigations are unavailable. Because the flaw is exploitable by a local authorized user, review which local or low-privilege accounts can access exposed Windows hosts while patching completes.
| microsoft Windows 10 | 1507 |
| microsoft Windows 10 | 1607 |
| microsoft Windows 10 | 1809 |
| microsoft Windows 10 | 21H2 |
| microsoft Windows 10 | 22H2 |
| microsoft Windows 11 | 22H2 |
| microsoft Windows 11 | 23H2 |
| microsoft Windows 11 | 24H2 |
| microsoft Windows Server 2008 | as listed in CPE (Windows Server 2008) |
| microsoft Windows Server 2012 | as listed in CPE (Windows Server 2012) |
| microsoft Windows Server 2016 | as listed in CPE (Windows Server 2016) |
| microsoft Windows Server 2019 | as listed in CPE (Windows Server 2019) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally.
- Affected
- Microsoft Windows
- Required action
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- microsoft
- Products
- windows 10 1507, windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 22h2, windows 11 23h2, windows 11 24h2, windows server 2008, windows server 2012, windows server 2016, windows server 2019
- Weakness
- CWE-125
- Vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N