← back
CVE-2025-24984

Windows NTFS Information Disclosure Vulnerability

CVSS 4.6 MEDIUMEPSS 1.8%● KEVCWE-532
In short

Windows NTFS stores sensitive information in log files that an attacker with physical access to the computer can read. This leaks private data that should be protected.

Technical detail

CWE-532 vulnerability where sensitive data is written to NTFS log files accessible via physical attack. An attacker with local disk access can extract confidential information from these logs, potentially compromising authentication credentials or system secrets. Requires physical presence or direct storage device access.

Summary generated and translated by AI from the official description.
Insertion of sensitive information into log file in Windows NTFS allows an unauthorized attacker to disclose information with a physical attack.
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:F/RL:O/RC:C

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →