HIGH
CVE-2025-24993
CVSS
7.8
KEV
Description
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.
Summary dbcve.org
A heap-based buffer overflow vulnerability exists in the Windows NTFS filesystem driver (NTFS.sys). An unauthenticated local attacker can exploit this memory corruption issue to execute arbitrary code with elevated privileges on the affected system. The vulnerability stems from improper bounds checking during NTFS filesystem operations.
Mitigation
Apply the Microsoft security update for CVE-2025-24993 to affected Windows systems. Prioritize patching systems where untrusted code or users have local access, as this is a local privilege escalation vulnerability.
Weakness (CWE)
CWE-122
Heap-based Buffer Overflow
EPSS Score
2.17%
Probability of exploitation in next 30 days
81.3th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.