CVE-2025-2489
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Mar 18, 2025
CWE ID 95
Summary
CVE-2025-2489 is an insecure information storage vulnerability affecting NTFS Tools version 3.5.1. An attacker who gains access to a user's Mac system can exploit this weakness and retrieve the application password, which is stored in the config.json file located in /Users/user/Library/Application Support/ntfs-tool/. This exposure can lead to unauthorized access or data theft. Users are encouraged to update to the latest version of NTFS Tools to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.