Vulnerability record · CVE-2025-24993 · published 11 March 2025
CVE-2025-24993: Windows NTFS heap buffer overflow enables local code execution
Microsoft · Windows 10 1507
CVE-2025-24993 is a heap-based buffer overflow in the Windows NTFS file system driver that lets an unauthorized attacker execute code locally. It affects a broad range of Windows client and server releases, and Microsoft rates it high severity (CVSS 7.8). Because NTFS is a core component, any code execution gained here runs with the privileges of the exploited process.
Description
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityThe vulnerability is confirmed exploited in the wild per CISA KEV and affects nearly all supported Windows versions, though it requires local access and user interaction, which limits mass exploitation.
What it is
CVE-2025-24993 is a heap-based buffer overflow in the Windows NTFS file system driver that lets an unauthorized attacker execute code locally. It affects a broad range of Windows client and server releases, and Microsoft rates it high severity (CVSS 7.8). Because NTFS is a core component, any code execution gained here runs with the privileges of the exploited process.
Impact
An attacker who triggers the overflow can execute arbitrary code on the target machine, with the confidentiality, integrity and availability impact rated high. The CVSS vector indicates the attacker does not need prior privileges, though user interaction is required.
Attack surface
The flaw is reached locally (AV:L) and requires user interaction (UI:R), with no privileges required (PR:N). In practice this means a crafted NTFS volume or file must be mounted or opened by the victim, for example via a malicious USB drive or downloaded image.
Exploitation
CVE-2025-24993 was added to CISA's Known Exploited Vulnerabilities catalog on 2025-03-11 with a remediation due date of 2025-04-01, confirming exploitation in the wild. EPSS gives a 30-day exploitation probability of about 2.2 percent (81st percentile), and CISA records no known ransomware campaign use.
What to do
- Apply the Microsoft security update for CVE-2025-24993 to all affected Windows 10, Windows 11 and Windows Server versions as the first action.
- Follow CISA BOD 22-01 guidance and meet the 2025-04-01 remediation deadline; discontinue use of unsupported builds that cannot be patched.
- Restrict mounting of untrusted removable media and disk images on endpoints and servers, and block autorun of external volumes where feasible.
- Limit local interactive access and use least-privilege accounts so a successful exploit runs with minimal rights.
Detection
- Monitor for unexpected crashes or bugchecks in NTFS-related components (ntfs.sys) that could indicate a failed overflow attempt.
- Alert on mounting of removable media or disk images from untrusted sources, especially on servers where such activity is unusual.
- Hunt for suspicious processes spawned shortly after a volume mount or file open on endpoints handling external media.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2025-24993 to the Known Exploited Vulnerabilities catalog on 11 March 2025 as "Microsoft Windows NTFS Heap-Based Buffer Overflow Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 1 April 2025.
Affected products
15 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-24993 | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-24993 | US Government Resource |
Track CVE-2025-24993 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2025-24993), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.