CVE CVE

CVE-2025-24984

CISA Known Exploited Vulnerability (KEV)

Microsoft Windows NTFS Information Disclosure Vulnerability

March 11, 2025

April 1, 2025

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Description

Insertion of sensitive information into log file in Windows NTFS allows an unauthorized attacker to disclose information with a physical attack.

Weakness Enumeration

CWE-ID CWE Name

CWE-532
Insertion of Sensitive Information into Log File

Details

Source:
NVD
Published:
Updated:

Risk information

CVSS v3

Base score:
4.6
Severity:

MEDIUM

Vector:
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CVSS v2

Not defined