CVE-2025-24993
KEVmassHeap-Based Buffer Overflow in Windows NTFS Enables Local Code Execution
CISA: Microsoft Windows NTFS Heap-Based Buffer Overflow Vulnerability
CVE-2025-24993 is a heap-based buffer overflow (CWE-122) in the Windows NTFS component that allows an unauthorized, unprivileged local attacker to execute code. Per the CVSS vector (AV:L/AC:L/PR:N/UI:R), exploitation occurs locally and requires user interaction, meaning an attacker must induce a user to interact with attacker-supplied content that corrupts NTFS heap memory. Successful exploitation gives the attacker code execution with high impact on confidentiality, integrity, and availability (CVSS 3.1 score 7.8). The affected range spans Windows 10 (1507 through 22H2), Windows 11 (22H2 through 24H2), and Windows Server 2008 through 2019, covering most of Microsoft's active desktop and server installed base. The flaw is being actively exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2025-03-11, and it was among the zero-days fixed in Microsoft's March 2025 Patch Tuesday, which addressed 57 vulnerabilities including six to seven actively exploited ones.
What to do: Apply Microsoft's March 2025 Patch Tuesday security updates (released 2025-03-11) to all affected Windows 10, Windows 11, and Windows Server systems immediately; as a KEV entry, this flaw must be remediated on U.S. federal systems per BOD 22-01 timelines, including applicable cloud-service guidance. Until patched, prioritize end-user endpoints and servers that process untrusted files or mounted media, verify patch status through vulnerability management tooling, and monitor for signs of local code execution. No public PoC is known, but confirmed in-the-wild exploitation makes patching urgent rather than optional.
| microsoft Windows 10 1507 | 1507 |
| microsoft Windows 10 1607 | 1607 |
| microsoft Windows 10 1809 | 1809 |
| microsoft Windows 10 21H2 | 21H2 |
| microsoft Windows 10 22H2 | 22H2 |
| microsoft Windows 11 22H2 | 22H2 |
| microsoft Windows 11 23H2 | 23H2 |
| microsoft Windows 11 24H2 | 24H2 |
| microsoft Windows Server 2008 | as listed by CISA; specific editions/service packs per Microsoft March 2025 advisory |
| microsoft Windows Server 2012 | as listed by CISA; specific editions per Microsoft March 2025 advisory |
| microsoft Windows Server 2016 | as listed by CISA; specific editions per Microsoft March 2025 advisory |
| microsoft Windows Server 2019 | as listed by CISA; specific editions per Microsoft March 2025 advisory |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.
- Affected
- Microsoft Windows
- Required action
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- microsoft
- Products
- windows 10 1507, windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 22h2, windows 11 23h2, windows 11 24h2, windows server 2008, windows server 2012, windows server 2016, windows server 2019
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H