ZeroHour

CVE-2025-24993

KEVmass

Heap-Based Buffer Overflow in Windows NTFS Enables Local Code Execution

CISA: Microsoft Windows NTFS Heap-Based Buffer Overflow Vulnerability

CVSS 3.1
7.8 high
EPSS
2%p81
Published
()
KEV added
AI analysis

CVE-2025-24993 is a heap-based buffer overflow (CWE-122) in the Windows NTFS component that allows an unauthorized, unprivileged local attacker to execute code. Per the CVSS vector (AV:L/AC:L/PR:N/UI:R), exploitation occurs locally and requires user interaction, meaning an attacker must induce a user to interact with attacker-supplied content that corrupts NTFS heap memory. Successful exploitation gives the attacker code execution with high impact on confidentiality, integrity, and availability (CVSS 3.1 score 7.8). The affected range spans Windows 10 (1507 through 22H2), Windows 11 (22H2 through 24H2), and Windows Server 2008 through 2019, covering most of Microsoft's active desktop and server installed base. The flaw is being actively exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2025-03-11, and it was among the zero-days fixed in Microsoft's March 2025 Patch Tuesday, which addressed 57 vulnerabilities including six to seven actively exploited ones.

What to do: Apply Microsoft's March 2025 Patch Tuesday security updates (released 2025-03-11) to all affected Windows 10, Windows 11, and Windows Server systems immediately; as a KEV entry, this flaw must be remediated on U.S. federal systems per BOD 22-01 timelines, including applicable cloud-service guidance. Until patched, prioritize end-user endpoints and servers that process untrusted files or mounted media, verify patch status through vulnerability management tooling, and monitor for signs of local code execution. No public PoC is known, but confirmed in-the-wild exploitation makes patching urgent rather than optional.

Affected
microsoft Windows 10 15071507
microsoft Windows 10 16071607
microsoft Windows 10 18091809
microsoft Windows 10 21H221H2
microsoft Windows 10 22H222H2
microsoft Windows 11 22H222H2
microsoft Windows 11 23H223H2
microsoft Windows 11 24H224H2
microsoft Windows Server 2008as listed by CISA; specific editions/service packs per Microsoft March 2025 advisory
microsoft Windows Server 2012as listed by CISA; specific editions per Microsoft March 2025 advisory
microsoft Windows Server 2016as listed by CISA; specific editions per Microsoft March 2025 advisory
microsoft Windows Server 2019as listed by CISA; specific editions per Microsoft March 2025 advisory
Estimated exposure
masshundreds of millions to over 1 billion Windows desktops and servers — The affected products span nearly the entire mainstream Windows line (Windows 10 and 11 client releases plus Windows Server 2008–2019), whose combined installed base is estimated at roughly a billion or more devices in enterprise and…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.

CISA Known Exploited Vulnerability
Affected
Microsoft Windows
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
microsoft
Products
windows 10 1507, windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 22h2, windows 11 23h2, windows 11 24h2, windows server 2008, windows server 2012, windows server 2016, windows server 2019
Weakness
CWE-122
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news