Zero-day vulnerability in Windows

Inclusion of Sensitive Information in Log Files
CVE-2025-24984

Vulnerability details

Advisory: SB2025031158 - Information disclosure in Windows NTFS

Vulnerable component: Windows

CVE-ID: CVE-2025-24984

CVSSv3 score: CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:H/RL:O/RC:C

CWE-ID: CWE-532 - Information Exposure Through Log Files

Description:

The vulnerability allows an attacker to gain access to sensitive information.

The vulnerability exists due to software stores sensitive information into log files. An attacker with physical access to the system can read the log files and gain access to sensitive data.

Note, the vulnerability is being actively exploited in the wild.

External links:

https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2025-24984