⚠ Actively exploited
Added to CISA KEV on 2025-03-11. Federal agencies required to patch by 2025-04-01. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable..
CVE-2025-24991 — Out-of-bounds Read in Microsoft Windows 10 Version 1507
Severity
5.5MEDIUMNVD
EPSS
0.5%
top 32.98%
CISA KEV
KEV
Added 2025-03-11
Due 2025-04-01
Exploit
No known exploits
Affected products
Timeline
PublishedMar 11
KEV addedMar 11
Latest updateMar 12
KEV dueApr 1
CISA Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Description
Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally.
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6
Affected Packages26 packages
🔴Vulnerability Details
3📋Vendor Advisories
2🕵️Threat Intelligence
10Tenable▶
Microsoft’s March 2025 Patch Tuesday Addresses 56 CVEs (CVE-2025-26633, CVE-2025-24983, CVE-2025-24993)↗2025-03-11