CVE-2025-24984
published 2025-03-11CVE-2025-24984: Insertion of sensitive information into log file in Windows NTFS allows an unauthorized attacker to disclose information with a physical attack.
PriorityP272medium4.6CVSS 3.1
AVPACLPRNUINSUCHINAN
KEVITW
CISA Known Exploited Vulnerabilitydue 2025-04-01
Exploited in the wild
EPSS
1.83%
76.5th percentile
Insertion of sensitive information into log file in Windows NTFS allows an unauthorized attacker to disclose information with a physical attack.
Affected
44 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10_1507 | < 10.0.10240.20947 | 10.0.10240.20947 |
| microsoft | windows_10_1607 | < 10.0.14393.7876 | 10.0.14393.7876 |
| microsoft | windows_10_1809 | < 10.0.17763.7009 | 10.0.17763.7009 |
| microsoft | windows_10_21h2 | < 10.0.19044.5608 | 10.0.19044.5608 |
| microsoft | windows_10_22h2 | < 10.0.19045.5608 | 10.0.19045.5608 |
| microsoft | windows_10_version_1507 | >= 10.0.10240.0 < 10.0.10240.20947 | 10.0.10240.20947 |
| microsoft | windows_10_version_1607 | >= 10.0.14393.0 < 10.0.14393.7876 | 10.0.14393.7876 |
| microsoft | windows_10_version_1809 | >= 10.0.17763.0 < 10.0.17763.7009 | 10.0.17763.7009 |
| microsoft | windows_10_version_21h2 | >= 10.0.19044.0 < 10.0.19044.5608 | 10.0.19044.5608 |
| microsoft | windows_10_version_22h2 | >= 10.0.19045.0 < 10.0.19045.5608 | 10.0.19045.5608 |
| microsoft | windows_11_22h2 | < 10.0.22621.5039 | 10.0.22621.5039 |
| microsoft | windows_11_23h2 | < 10.0.22631.5039 | 10.0.22631.5039 |
| microsoft | windows_11_24h2 | < 10.0.26100.3403 | 10.0.26100.3403 |
| microsoft | windows_11_version_22h2 | >= 10.0.22621.0 < 10.0.22621.5039 | 10.0.22621.5039 |
| microsoft | windows_11_version_22h3 | >= 10.0.22631.0 < 10.0.22631.5039 | 10.0.22631.5039 |
| microsoft | windows_11_version_23h2 | >= 10.0.22631.0 < 10.0.22631.5039 | 10.0.22631.5039 |
| microsoft | windows_11_version_24h2 | >= 10.0.26100.0 < 10.0.26100.3476 | 10.0.26100.3476 |
| microsoft | windows_server_2012 | — | — |
| microsoft | windows_server_2012 | >= 6.2.9200.0 < 6.2.9200.25368 | 6.2.9200.25368 |
| microsoft | windows_server_2012_r2 | >= 6.3.9600.0 < 6.3.9600.22470 | 6.3.9600.22470 |
| microsoft | windows_server_2016 | < 10.0.14393.7876 | 10.0.14393.7876 |
| microsoft | windows_server_2016 | >= 10.0.14393.0 < 10.0.14393.7876 | 10.0.14393.7876 |
| microsoft | windows_server_2019 | < 10.0.17763.7009 | 10.0.17763.7009 |
| microsoft | windows_server_2019 | >= 10.0.17763.0 < 10.0.17763.7009 | 10.0.17763.7009 |
| microsoft | windows_server_2022 | < 10.0.20348.3270 | 10.0.20348.3270 |
Detection & IOCsextracted from sources · hover to see the quote
- →Attack vector is physical — attacker must plug in a malicious USB drive to the target machine to trigger NTFS log file information disclosure ↗
- →Successful exploitation leaks heap memory contents via Windows NTFS log file insertion; monitor for unexpected NTFS log ($LogFile) access or reads from physical/removable media mount events ↗
- →CVE-2025-24984 is confirmed actively exploited in the wild — prioritize detection of USB device plug-in events on sensitive Windows hosts combined with NTFS log file access ↗
- ·Attack vector is Physical (AV:P) — exploitation requires the attacker to have hands-on access to the target machine; remote exploitation is not applicable for this CVE ↗
- ·The vulnerability is in Windows NTFS specifically (insertion of sensitive information into log file); scope is limited to the NTFS driver's log handling, not a general Windows logging subsystem ↗
CVSS provenance
nvdv3.14.6MEDIUMCVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
vulncheck4.6MEDIUM
cisa4.6MEDIUM
vendor_msrc4.6MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA
Microsoft Windows NTFS Information Disclosure Vulnerability
cisa·2025-03-11·CVSS 4.6
CVE-2025-24984 [MEDIUM] CWE-532 Microsoft Windows NTFS Information Disclosure Vulnerability
Vulnerability: Microsoft Windows NTFS Information Disclosure Vulnerability
Affected: Microsoft Windows
Microsoft Windows New Technology File System (NTFS) contains an insertion of sensitive Information into log file vulnerability that allows an unauthorized attacker to disclose information with a physical attack. An attacker who successfully exploited this vulnerability could potentially read portions of heap memory.
Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Notes: https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2025-24984 ; https://nvd.nist.gov/vuln/detail/CVE-2025-24984
Remediation Due Date: 2025-04-01
Microsoft
Windows NTFS Information Disclosure Vulnerability
vendor_msrc·2025-03-11·CVSS 4.6
CVE-2025-24984 [MEDIUM] CWE-532 Windows NTFS Information Disclosure Vulnerability
Windows NTFS Information Disclosure Vulnerability
Description: Insertion of sensitive information into log file in Windows NTFS allows an unauthorized attacker to disclose information with a physical attack.
FAQ: According to the CVSS metric, the Attack Vector is Physical (AV:P). What does that mean for this vulnerability?
An attacker needs physical access to the target computer to plug in a malicious USB drive.
FAQ: What type of information could be disclosed by this vulnerability?
An attacker who successfully exploited this vulnerability could potentially read portions of heap memory.
Windows NTFS: Windows NTFS
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Information Disclosure
Exploit Status: Publicly Disclosed:No;Exploited:Yes;Latest Software Release:Exploitation
GHSA
GHSA-2q4f-gjpq-vfmh: Insertion of sensitive information into log file in Windows NTFS allows an unauthorized attacker to disclose information with a physical attack
ghsa_unreviewed·2025-03-11
CVE-2025-24984 [MEDIUM] CWE-532 GHSA-2q4f-gjpq-vfmh: Insertion of sensitive information into log file in Windows NTFS allows an unauthorized attacker to disclose information with a physical attack
Insertion of sensitive information into log file in Windows NTFS allows an unauthorized attacker to disclose information with a physical attack.
VulnCheck
Microsoft Windows NTFS Information Disclosure Vulnerability
vulncheck·2025·CVSS 4.6
CVE-2025-24984 [MEDIUM] CWE-532 Microsoft Windows NTFS Information Disclosure Vulnerability
Microsoft Windows NTFS Information Disclosure Vulnerability
Microsoft Windows New Technology File System (NTFS) contains an insertion of sensitive Information into log file vulnerability that allows an unauthorized attacker to disclose information with a physical attack. An attacker who successfully exploited this vulnerability could potentially read portions of heap memory.
Affected: Microsoft Windows
Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Exploitation References: https://api.msrc.microsoft.com/cvrf/v3.0/cvrf/2025-Mar; https://docs.google.com/spreadsheets/d/1lkNJ0uQwbeC1ZTRrxdtuPLCIl7mlUreoKfSIgajnSyY/edit; https://msrc.microsoft.com/update-gu
No detection rules found.
No public exploits indexed.
Bleepingcomputer
Microsoft patches Windows Kernel zero-day exploited since 2023
blogs_bleepingcomputer·2025-03-12·CVSS 7.8
CVE-2025-24983 [HIGH] Microsoft patches Windows Kernel zero-day exploited since 2023
## Microsoft patches Windows Kernel zero-day exploited since 2023
## Sergiu Gatlan
ESET said on Tuesday that a zero-day exploit targeting the CVE-2025-24983 vulnerability was "first seen in the wild" in March 2023 on systems backdoored using PipeMagic malware.
This exploit targets only older Windows versions (Windows Server 2012 R2 and Windows 8.1) that Microsoft no longer supports. However, the vulnerability also affects newer Windows versions, including the still-supported Windows Server 2016 and Windows 10 systems running Windows 10 build 1809 and earlier.
"The Use-After-Free (UAF) vulnerability is related to improper memory usage during software operation. This can lead to software crashes, execution of malicious code (including remotely), privilege escalation, or data corruption,"
Krebs
Microsoft: 6 Zero-Days in March 2025 Patch Tuesday
blogs_krebs·2025-03-12·CVSS 7.0
CVE-2025-24991 [HIGH] Microsoft: 6 Zero-Days in March 2025 Patch Tuesday
Microsoft today issued more than 50 security updates for its various Windows operating systems, including fixes for a whopping six zero-day vulnerabilities that are already seeing active exploitation.
Two of the zero-day flaws include CVE-2025-24991 and CVE-2025-24993, both vulnerabilities in NTFS, the default file system for Windows and Windows Server. Both require the attacker to trick a target into mounting a malicious virtual hard disk. CVE-2025-24993 would lead to the possibility of local code execution, while CVE-2025-24991 could cause NTFS to disclose portions of memory.
Microsoft credits researchers at ESET with reporting the zero-day bug labeled CVE-2025-24983, an elevation of privilege vulnerability in older versions of Windows. ESET said the exploit was deployed via the PipeMa
Qualys
Microsoft and Adobe Patch Tuesday, March 2025 Security Update Review
blogs_qualys·2025-03-11
Microsoft and Adobe Patch Tuesday, March 2025 Security Update Review
## Table of Contents
Microsoft Patch Tuesday for March 2025
Adobe Patches for March 2025
Zero-day Vulnerabilities Patched in March Patch Tuesday Edition
Critical Severity Vulnerabilities Patched in March Patch Tuesday Edition
Other Microsoft Vulnerability Highlights
Microsoft Release Summary
Discover and Prioritize Vulnerabilities inVulnerability Management, Detection & Response (VMDR)
Rapid Response withPatch Management (PM)
EVALUATE Vendor-Suggested Mitigation with Policy Compliance (PC)
Risk Reduction via TruRisk Eliminate
Qualys Monthly Webinar Series
March 2025 Patch Tuesday is here, and Microsoft has rolled out critical security updates that address multiple vulnerabilities across its product suite. Here’s a quick breakdown of what you need to know.
## Microsoft Patch Tu
Talos
Microsoft Patch Tuesday for March 2025 — Snort rules and prominent vulnerabilities
blogs_talos·2025-03-11·CVSS 7.8
CVE-2025-26633 [HIGH] Microsoft Patch Tuesday for March 2025 — Snort rules and prominent vulnerabilities
## Microsoft Patch Tuesday for March 2025 — Snort rules and prominent vulnerabilities
Microsoft has released its monthly security update for March of 2025 which includes 57 vulnerabilities affecting a range of products, including 6 that Microsoft marked as “critical”.
There are six vulnerabilities that Microsoft has observed being exploited in the wild. CVE-2025-26633 is a Remoted Code Execution (RCE) vulnerability in Microsoft’s Management Console. Two information disclosure vulnerabilities, CVE-2025-24984 and CVE-2025-24991 , and one RCE vulnerability, CVE-2025-24993 , in Windows NTFS were observed being exploited in the wild. Microsoft also patched, CVE-2025-24985 , another RCE exploited in the wild in the Windows Fast FAT system driver. An Elevation of Privilege (EOP) vulnerability,
Tenable
Microsoft’s March 2025 Patch Tuesday Addresses 56 CVEs (CVE-2025-26633, CVE-2025-24983, CVE-2025-24993)
blogs_tenable·2025-03-11·CVSS 7.0
[HIGH] Microsoft’s March 2025 Patch Tuesday Addresses 56 CVEs (CVE-2025-26633, CVE-2025-24983, CVE-2025-24993)
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Krebs
Microsoft: 6 Zero-Days in March 2025 Patch Tuesday
blogs_krebs·2025-03-11·CVSS 7.0
CVE-2025-24991 [HIGH] Microsoft: 6 Zero-Days in March 2025 Patch Tuesday
Microsoft today issued more than 50 security updates for its various Windows operating systems, including fixes for a whopping six zero-day vulnerabilities that are already seeing active exploitation.
Two of the zero-day flaws include CVE-2025-24991 and CVE-2025-24993 , both vulnerabilities in NTFS , the default file system for Windows and Windows Server. Both require the attacker to trick a target into mounting a malicious virtual hard disk. CVE-2025-24993 would lead to the possibility of local code execution, while CVE-2025-24991 could cause NTFS to disclose portions of memory.
Microsoft credits researchers at ESET with reporting the zero-day bug labeled CVE-2025-24983 , an elevation of privilege vulnerability in older versions of Windows. ESET said the exploit was deployed via the Pip
Talos
Microsoft Patch Tuesday for March 2025 — Snort rules and prominent vulnerabilities
blogs_talos·2025-03-11·CVSS 7.8
CVE-2025-26633 [HIGH] Microsoft Patch Tuesday for March 2025 — Snort rules and prominent vulnerabilities
Microsoft has released its monthly security update for March of 2025 which includes 57 vulnerabilities affecting a range of products, including 6 that Microsoft marked as “critical”.
There are six vulnerabilities that Microsoft has observed being exploited in the wild. CVE-2025-26633 is a Remoted Code Execution (RCE) vulnerability in Microsoft’s Management Console. Two information disclosure vulnerabilities, CVE-2025-24984 and CVE-2025-24991, and one RCE vulnerability, CVE-2025-24993, in Windows NTFS were observed being exploited in the wild. Microsoft also patched, CVE-2025-24985, another RCE exploited in the wild in the Windows Fast FAT system driver. An Elevation of Privilege (EOP) vulnerability, CVE-2025-24983, was also discovered being exploited in the wild, in Windows’ win32 Kernel
Qualys
Microsoft and Adobe Patch Tuesday, March 2025 Security Update Review | Qualys
blogs_qualys·2025-03-11
Microsoft and Adobe Patch Tuesday, March 2025 Security Update Review | Qualys
#### Table of Contents
- Microsoft Patch Tuesday for March 2025
- Adobe Patches for March 2025
- Zero-day Vulnerabilities Patched in March Patch Tuesday Edition
- Critical Severity Vulnerabilities Patched in March Patch Tuesday Edition
- Other Microsoft Vulnerability Highlights
- Microsoft Release Summary
- Discover and Prioritize Vulnerabilities inVulnerability Management, Detection & Response (VMDR)
- Rapid Response withPatch Management (PM)
- EVALUATE Vendor-Suggested Mitigation with Policy Compliance (PC)
- Risk Reduction via TruRisk Eliminate
- Qualys Monthly Webinar Series
March 2025 Patch Tuesday is here, and Microsoft has rolled out critical security updates that address multiple vulnerabilities across its product suite. Here’s a quick breakdown of what you need to know.
## Micr
Bleepingcomputer
Microsoft March 2025 Patch Tuesday fixes 7 zero-days, 57 flaws
blogs_bleepingcomputer·2025-03-11·CVSS 7.0
[HIGH] Microsoft March 2025 Patch Tuesday fixes 7 zero-days, 57 flaws
## Microsoft March 2025 Patch Tuesday fixes 7 zero-days, 57 flaws
## Lawrence Abrams
23 Elevation of Privilege Vulnerabilities
3 Security Feature Bypass Vulnerabilities
23 Remote Code Execution Vulnerabilities
4 Information Disclosure Vulnerabilities
1 Denial of Service Vulnerabilities
3 Spoofing Vulnerabilities
The above numbers do not include Mariner flaws and 10 Microsoft Edge vulnerabilities fixed earlier this month.
To learn more about the non-security updates released today, you can review our dedicated articles on the Windows 11 KB5053598 & KB5053602 cumulative updates and the Windows 10 KB5053606 update .
## Six actively exploited zero-days
This month's Patch Tuesday fixes six actively exploited zero-days and one that was publicly exposed, for a total of seven zero-days.
Crowdstrike
March 2025 Patch Tuesday: Updates and Analysis
blogs_crowdstrike·CVSS 7.5
CVE-2026-20929 [HIGH] March 2025 Patch Tuesday: Updates and Analysis
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand ATT&CK in 10 Minutes or Less [VI
2025-03-11
Published
2025-03-11
Added to CISA KEV
Exploited in the wild