LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2025-24991: Microsoft Windows NTFS Out-Of-Bounds Read Vulnerability

RBRecent Breaches Vulnerability Intelligence·Mar 11, 2025
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Apr 1, 2025
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2025-24991 to its Known Exploited Vulnerabilities catalog on Mar 11, 2025, with a federal patch deadline of Apr 1, 2025 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Microsoft Windows New Technology File System (NTFS) contains an out-of-bounds read vulnerability that allows an authorized attacker to disclose information locally.

CVE-2025-24991 is an out-of-bounds read vulnerability in the Microsoft Windows New Technology File System (NTFS). An authorized attacker with local access can use it to disclose information from the system.

Information disclosure flaws of this type matter because they can reveal memory contents, configuration details, or other sensitive data that help an attacker plan follow-on actions. Because the vulnerability requires local authorization, it is most relevant on multi-user systems, shared workstations, or environments where untrusted code or users already have a foothold.

How it works

The underlying weakness is CWE-125 (out-of-bounds read). In this class of flaw, software reads data past the end of an allocated buffer or structure. When the Windows NTFS component mishandles certain inputs or operations, an authorized local attacker can trigger a read that returns data outside the intended bounds.

The result is information disclosure rather than remote code execution. The attacker does not need to invent complex network payloads; they need only local access and the ability to interact with the affected NTFS path or interface. Exact trigger conditions and any required privileges must be confirmed against the vendor advisory; public detail beyond the CISA summary is limited.

Am I affected? How to find it in your systems

Microsoft Windows systems that use NTFS are in scope. NTFS is the default file system on the vast majority of Windows client and server installations, so the vulnerability potentially applies broadly across enterprise fleets.

Because exploitation is local, network scanners will not detect the vulnerability itself; host-based inventory and patch status are the primary indicators of exposure.

How to remediate

The primary remediation is to apply the security update provided by Microsoft for this CVE. Follow the vendor instructions exactly, including any prerequisite updates or reboot requirements.

CISA guidance for this vulnerability is to apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Confirm all version-specific details against the official Microsoft advisory.

If you can't patch immediately

Until the vendor update can be applied, reduce the attack surface with compensating controls appropriate to a local out-of-bounds read:

These measures lower risk but do not eliminate it. Prioritize patching as soon as operationally feasible.

If your data may have been exposed

Actively exploited vulnerabilities can lead to broader compromise and data exposure even when the initial flaw is only information disclosure. If you have reason to believe systems were targeted before patching, treat the incident according to your standard response process: isolate affected hosts, preserve forensic evidence, and assess what data may have been accessible to the attacker.

You can also run a free exposure scan of your email addresses against known breach data sets to determine whether credentials or personal information associated with your organization already appear in public breach corpora. Combine that check with internal log review and endpoint forensics for a more complete picture.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMicrosoft · Windows
WeaknessCWE-125
Added to CISA KEVMar 11, 2025
Federal patch deadlineApr 1, 2025
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities