Vulnerability record · CVE-2025-24984 · published 11 March 2025
CVE-2025-24984: Windows NTFS logs sensitive information, enabling physical-attack disclosure
Microsoft · Windows 10 1507
Windows NTFS writes sensitive information into a log file, which an attacker can read to disclose data. The flaw is rated CVSS 3.1 4.6 (Medium) and affects a broad set of Windows 10, Windows 11 and Windows Server releases. It matters because the affected code is present across nearly all supported Windows versions, though exploitation requires physical access to the machine.
Description
Insertion of sensitive information into log file in Windows NTFS allows an unauthorized attacker to disclose information with a physical attack.
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Automated analysis
medium priorityCVSS is only 4.6 and the vector requires physical access, but CISA KEV listing means it is known-exploited and a patch deadline applies.
What it is
Windows NTFS writes sensitive information into a log file, which an attacker can read to disclose data. The flaw is rated CVSS 3.1 4.6 (Medium) and affects a broad set of Windows 10, Windows 11 and Windows Server releases. It matters because the affected code is present across nearly all supported Windows versions, though exploitation requires physical access to the machine.
Impact
An attacker who can reach the machine physically gains disclosure of sensitive information written to the NTFS log; there is no integrity or availability impact. The confidentiality impact is rated High, so the leaked data could be meaningful rather than trivial.
Attack surface
The CVSS vector is AV:P/AC:L/PR:N/UI:N, so the attack requires physical access to the target system, needs no authentication and no user interaction. It is not remotely reachable over a network.
Exploitation
CISA added it to the KEV catalog on 2025-03-11 with a remediation due date of 2025-04-01, indicating known exploitation, while EPSS puts 30-day exploitation probability at about 2.0 percent (79th percentile). No ransomware campaign use is documented.
What to do
- Apply the Microsoft update listed in the MSRC advisory for CVE-2025-24984 across all affected Windows 10, Windows 11 and Windows Server builds.
- Follow CISA BOD 22-01 guidance and meet the 2025-04-01 remediation due date, or discontinue use of the product if mitigations are unavailable.
- Restrict and monitor physical access to systems holding sensitive data, since the attack vector is physical.
- Verify patch coverage for the long list of affected builds, including older Windows 10 1507/1607/1809 and Windows Server 2012/2016, which are easy to miss.
Detection
- Review NTFS log and metadata artifacts on sensitive endpoints for unexpected or anomalous content that could indicate sensitive data written to disk.
- Audit physical access logs and console or USB activity on systems that store high-value data, correlating with any signs of NTFS log inspection.
- Track patch compliance for CVE-2025-24984 across all affected Windows builds and flag unpatched hosts.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2025-24984 to the Known Exploited Vulnerabilities catalog on 11 March 2025 as "Microsoft Windows NTFS Information Disclosure Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 1 April 2025.
Affected products
14 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-24984 | PatchVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-24984 | US Government Resource |
Track CVE-2025-24984 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2025-24984), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.