MEDIUM
CVE-2025-24991
CVSS
5.5
KEV
Description
Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally.
Summary dbcve.org
An out-of-bounds read vulnerability in Windows NTFS allows a local authorized attacker to read memory beyond allocated boundaries, potentially exposing sensitive information from kernel memory.
Mitigation
Apply the relevant Microsoft Windows security update for this vulnerability through standard patch management processes; this is a kernel-level file system patch requiring thorough testing in staging environments before production deployment.
Weakness (CWE)
CWE-125
Out-of-bounds Read
EPSS Score
1.98%
Probability of exploitation in next 30 days
79.6th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.