{"cveID":"CVE-2025-24991","vendorProject":"Microsoft","product":"Windows","vulnerabilityName":"Microsoft Windows NTFS Out-Of-Bounds Read Vulnerability","dateAdded":"2025-03-11","shortDescription":"Microsoft Windows New Technology File System (NTFS) contains an out-of-bounds read vulnerability that allows an authorized attacker to disclose information locally.","requiredAction":"Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.","dueDate":"2025-04-01","knownRansomwareCampaignUse":"Unknown","notes":"https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2025-24991 ; https://nvd.nist.gov/vuln/detail/CVE-2025-24991","cwes":["CWE-125"],"year":2025,"state":"mapped","stale_reasons":[],"mappings":[{"domain":"enterprise","cve":"CVE-2025-24991","technique":"T1091","technique_name_at_mapping":"Replication Through Removable Media","mapping_type":"exploitation_technique","capability_group":"oob","comments":"This vulnerability is facilitated by the insertion of information into log files, which could lead to the disclosure of said sensitive information through an attack. In order to exploit this vulnerability, an attacker needs physical access to the system, such as the ability to mount an external drive.","references":["https://www.redlegg.com/blog/critical-vulnerability-patch-tuesday-march-2025"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"},{"domain":"enterprise","cve":"CVE-2025-24991","technique":"T1005","technique_name_at_mapping":"Data from Local System","mapping_type":"primary_impact","capability_group":"oob","comments":"This vulnerability is facilitated by the insertion of information into log files, which could lead to the disclosure of said sensitive information through an attack. In order to exploit this vulnerability, an attacker needs physical access to the system, such as the ability to mount an external drive.","references":["https://www.redlegg.com/blog/critical-vulnerability-patch-tuesday-march-2025"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"}],"techniques":[{"id":"T1005","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Data from Local System","name_at_mapping":"Data from Local System","renamed":false,"revoked_by":null,"mapping_types":["primary_impact"],"sigma_rule_count":14,"has_detection_strategy":true},{"id":"T1091","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Replication Through Removable Media","name_at_mapping":"Replication Through Removable Media","renamed":false,"revoked_by":null,"mapping_types":["exploitation_technique"],"sigma_rule_count":1,"has_detection_strategy":true}],"mapping_types":["exploitation_technique","primary_impact"],"has_exploitation_technique":true,"mapping_attack_versions":["16.1"],"mapping_domains":["enterprise"],"sigma_coverage":"full","sigma_rules_tagged_cve":[],"added_after_mapping_snapshot":false,"_source":"kevmap","_built":"2026-08-23 05:47 UTC","_attack_version":"19.2"}