LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2025-24984: Microsoft Windows NTFS Information Disclosure Vulnerability

RBRecent Breaches Vulnerability Intelligence·Mar 11, 2025
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Apr 1, 2025
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2025-24984 to its Known Exploited Vulnerabilities catalog on Mar 11, 2025, with a federal patch deadline of Apr 1, 2025 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Microsoft Windows New Technology File System (NTFS) contains an insertion of sensitive Information into log file vulnerability that allows an unauthorized attacker to disclose information with a…

CVE-2025-24984 is an information disclosure vulnerability in Microsoft Windows NTFS that stems from sensitive data being written into log files. An unauthorized attacker with physical access could exploit it to disclose information, potentially reading portions of heap memory. This matters because even limited memory disclosure can leak credentials, keys, or other secrets that enable further compromise on Windows systems that rely on NTFS.

Defenders should treat it as a local, physical-access risk that still warrants prompt patching and inventory, especially on devices that leave controlled environments. Confirm all version and configuration details against the vendor advisory before acting.

How it works

The flaw is classified as CWE-532, insertion of sensitive information into a log file. In this case the Microsoft Windows New Technology File System (NTFS) component writes data that should remain protected into logs that an attacker can later access. With physical access an unauthorized attacker can retrieve those logs and extract the sensitive material, which the advisory states may include portions of heap memory.

No remote network exploitation path is described in the available facts; the attack requires physical presence. Exact trigger conditions, log locations, and memory contents are not detailed here and must be confirmed against the Microsoft advisory. The result is classic information disclosure rather than code execution or privilege escalation.

Am I affected? How to find it in your systems

Microsoft Windows systems that use NTFS are in scope. NTFS is the default file system on virtually all modern Windows client and server installations, so the vulnerability potentially applies across desktops, laptops, workstations, and servers running supported Windows versions.

If your management tools cannot report exact patch status, treat unpatched Windows systems as potentially affected until you verify them against the vendor advisory.

How to remediate

Apply the security update Microsoft released for this vulnerability as the primary remediation. Follow the vendor instructions exactly; the CISA required action is to apply mitigations per those instructions, follow applicable BOD 22-01 guidance for any cloud-hosted Windows instances, or discontinue use of the product if mitigations are unavailable.

Do not rely on workarounds alone; the vendor patch is the definitive fix.

If you can't patch immediately

Until the update can be applied, reduce exposure with compensating controls focused on physical access and log protection.

These measures lower risk but do not eliminate it; schedule the official patch as soon as operationally feasible.

If your data may have been exposed

Actively exploited vulnerabilities can lead to breaches even when the initial vector is information disclosure. If physical access to an affected system is suspected, treat any credentials, keys, or secrets that may have resided in memory as compromised: rotate them, review access logs, and investigate for follow-on activity. Known ransomware use of this CVE is not documented. As a quick additional check, you can run a free exposure scan of your email addresses against known breach data sets to see whether related accounts already appear in public dumps.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMicrosoft · Windows
WeaknessCWE-532
Added to CISA KEVMar 11, 2025
Federal patch deadlineApr 1, 2025
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities