CVE-2025-24984

Published Mar 11, 2025

Last updated 22 days ago

Overview

Description
Insertion of sensitive information into log file in Windows NTFS allows an unauthorized attacker to disclose information with a physical attack.
Source
secure@microsoft.com
NVD status
Analyzed

Risk scores

CVSS 3.1

Type
Primary
Base score
4.6
Impact score
3.6
Exploitability score
0.9
Vector string
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Severity
MEDIUM

Known exploits

Data from CISA

Vulnerability name
Microsoft Windows NTFS Information Disclosure Vulnerability
Exploit added on
Mar 11, 2025
Exploit action due
Apr 1, 2025
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weaknesses

secure@microsoft.com
CWE-532

Social media

Hype score
Not currently trending
  1. Actively exploited CVE : CVE-2025-24984

    @transilienceai

    22 Mar 2025

    14 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. Microsoft's March Patch Tuesday addresses 67 vulnerabilities, including six zero-days under active exploitation. Notably, three NTFS flaws (CVE-2025-24984, CVE-2025-24991, CVE-2025-24993) could allow attackers to access sensitive data or execute code via malicious VHDs.

    @TuringCyberObs

    21 Mar 2025

    31 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    1 Reply

    0 Quotes

  3. Actively exploited CVE : CVE-2025-24984

    @transilienceai

    21 Mar 2025

    7 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  4. Actively exploited CVE : CVE-2025-24984

    @transilienceai

    19 Mar 2025

    13 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  5. Actively exploited CVE : CVE-2025-24984

    @transilienceai

    17 Mar 2025

    7 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  6. Actively exploited CVE : CVE-2025-24984

    @transilienceai

    16 Mar 2025

    8 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  7. آسیب پذیری جدیدی با کد شناسایی CVE-2025-24984 برای فایل سیستم NTFS در ویندوز منتشر شده است. آسیب پذیری از نوع information disclosure می باشد و به هکرها امکان سرقت اطلاعات را می دهند. برای پیشگیری و مقابله با این تهدید به روز رسانی لازم را اعمال نمایید. https://t.co/Poz3aKYxT1 ht

    @AmirHossein_sec

    15 Mar 2025

    20 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. 🔴 #Windows NTFS, Information Disclosure Vulnerability, #CVE-2025-24984 (Critical) https://t.co/JchanNuC5I

    @dailycve

    13 Mar 2025

    12 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  9. CVE-2025-24984 Insertion of sensitive information into log file in Windows NTFS allows an unauthorized attacker to disclose information with a physical attack. https://t.co/wlNcl0Bfsl

    @CVEnew

    11 Mar 2025

    152 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations