CVE-2025-24984
Microsoft · Published March 11, 2025
4.6
CVSS v3.1
MEDIUMCISA KEV — Federal agencies must patch by deadline
Actively exploited in the wild
Patch availableGet patch
Description
Insertion of sensitive information into log file in Windows NTFS allows an unauthorized attacker to disclose information with a physical attack.
Affected Products
- Windows 10 1507 < 10.0.10240.20947
- Windows 10 1607 < 10.0.14393.7876
- Windows 10 1809 < 10.0.17763.7009
- Windows 10 21h2 < 10.0.19044.5608
CVSS Vector
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N