CVE-2025-24993
CVSS 3.1 Score 7.8 of 10 (high)
Details
Published Mar 11, 2025
Updated: Mar 13, 2025
CWE ID 122
Summary
CVE-2025-24993 is a newly disclosed vulnerability affecting the Windows NTFS file system. This issue involves a heap-based buffer overflow, allowing malicious actors to execute arbitrary code locally on an affected system. Exploitation of this vulnerability could lead to the installation of unauthorized software, data theft, or other malicious activities. The precise conditions required to trigger the vulnerability are still under investigation, but it is recommended that Windows users apply available patches as soon as possible to mitigate the risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.