Microsoft Windows NTFS Heap-Based Buffer Overflow Vulnerability

cve CVE-2025-24993 2 sources, 2 claims · Watch

CISA Known Exploited Vulnerabilities writes:
Microsoft Windows NTFS Heap-Based Buffer Overflow Vulnerability Microsoft Windows New Technology File System (NTFS) contains a heap-based buffer overflow vulnerability that allows an unauthorized attacker to execute code locally. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2025-24993 ; https://nvd.nist.gov/vuln/detail/CVE-2025-24993 the claim
Severity
HIGH NVD
CVSS
7.8 NVD
Exploited
yes CISA Known Exploited Vulnerabilities
Known ransomware campaign use
Unknown CISA Known Exploited Vulnerabilities
Due date
2025-04-01 CISA Known Exploited Vulnerabilities
Fixed in
10.0.10240.20947, 10.0.14393.7876, 10.0.17763.7009, 10.0.19044.5608, 10.0.19045.5608, 10.0.22621.5039, 10.0.22631.5039, 10.0.26100.3476, 6.1.7601.27618, 6.0.6003.23168, 6.2.9200.25368, 6.3.9600.22470, 10.0.20348.3328, 10.0.25398.1486 NVD
Vendor
Microsoft CISA Known Exploited Vulnerabilities
Microsoft NVD
Product
Windows CISA Known Exploited Vulnerabilities
Windows 10 Version 1507 NVD
CWE
CWE-122 CISA Known Exploited Vulnerabilities
CWE-122 NVD

How far exploitation has got

  1. No public code known
  2. Proof of concept
  3. Proof of concept, verified
  4. A Metasploit module
  5. Exploited in the wild · CISA Known Exploited Vulnerabilities 2025-03-11
  6. Used in ransomware campaigns

Timeline

2025-03-11first spoke of it: Microsoft Windows NTFS Heap-Based Buffer Overflow VulnerabilityCISA Known Exploited Vulnerabilities
2025-03-11first spoke of it: Microsoft Windows NTFS Heap-Based Buffer Overflow VulnerabilityNVD
2025-04-01Due dateCISA Known Exploited Vulnerabilities

What it is to other things

affectsmicrosoft/windows_10_1507
NVD
affectsmicrosoft/windows_10_1607
NVD
affectsmicrosoft/windows_10_1809
NVD
affectsmicrosoft/windows_10_21h2
NVD
affectsmicrosoft/windows_10_22h2
NVD
affectsmicrosoft/windows_11_22h2
NVD
affectsmicrosoft/windows_11_23h2
NVD
affectsmicrosoft/windows_11_24h2
NVD
affectsmicrosoft/windows_server_2008
NVD
affectsmicrosoft/windows_server_2012
NVD
affectsmicrosoft/windows_server_2016
NVD
affectsmicrosoft/windows_server_2019
NVD
affectsmicrosoft/windows_server_2022
NVD
affectsmicrosoft/windows_server_2022_23h2
NVD
affectsmicrosoft/windows_server_2025
NVD
made_bymicrosoft
NVD

In words only, so not counted until a person confirms one:

affectsmicrosoft/windows
CISA Known Exploited Vulnerabilities says “Microsoft · Windows”
affectsmicrosoft/windows_10_version_1507
NVD says “Microsoft · Windows 10 Version 1507”
Every value, with what each source said and its receipt
PropertySourceSaidMeans here
Automatable
automatable
NVDno
At least one of those steps needs a person.
receipt
Source
NVD
Its words
no
Read by
field:cve.metrics.ssvcV203[].ssvcData.options[].automatable
Said since
2026-10-06 11:54 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 11:54 UTCno
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "platforms": [
              "32-bit Systems",
              "x64-based Systems"
            ],
            "product": "Windows 10 Version 1507",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.10240.20947",
                "status": "affected",
                "version": "10.0.10240.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "32-bit Systems",
              "x64-based Systems"
            ],
            "product": "Windows 10 Version 1607",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.14393.7876",
                "status": "affected",
                "version": "10.0.14393.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "32-bit Systems",
              "x64-based Systems"
            ],
            "product": "Windows 10 Version 1809",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.17763.7009",
                "status": "affected",
                "version": "10.0.17763.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "32-bit Systems",
              "ARM64-based Systems",
              "x64-based Systems"
            ],
            "product": "Windows 10 Version 21H2",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.19044.5608",
                "status": "affected",
                "version": "10.0.19044.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "32-bit Systems",
              "ARM64-based Systems",
              "x64-based Systems"
            ],
            "product": "Windows 10 Version 22H2",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.19045.5608",
                "status": "affected",
                "version": "10.0.19045.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "ARM64-based Systems",
              "x64-based Systems"
            ],
            "product": "Windows 11 version 22H2",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.22621.5039",
                "status": "affected",
                "version": "10.0.22621.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "ARM64-based Systems"
            ],
            "product": "Windows 11 version 22H3",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.22631.5039",
                "status": "affected",
                "version": "10.0.22631.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows 11 Version 23H2",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.22631.5039",
                "status": "affected",
                "version": "10.0.22631.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "ARM64-based Systems",
              "x64-based Systems"
            ],
            "product": "Windows 11 Version 24H2",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.26100.3476",
                "status": "affected",
                "version": "10.0.26100.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2008 R2 Service Pack 1",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "6.1.7601.27618",
                "status": "affected",
                "version": "6.1.7601.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2008 R2 Service Pack 1 (Server Core installation)",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "6.1.7601.27618",
                "status": "affected",
                "version": "6.1.7601.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "32-bit Systems",
              "x64-based Systems"
            ],
            "product": "Windows Server 2008 Service Pack 2",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "6.0.6003.23168",
                "status": "affected",
                "version": "6.0.6003.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "32-bit Systems",
              "x64-based Systems"
            ],
            "product": "Windows Server 2008 Service Pack 2 (Server Core installation)",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "6.0.6003.23168",
                "status": "affected",
                "version": "6.0.6003.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2012",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "6.2.9200.25368",
                "status": "affected",
                "version": "6.2.9200.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2012 (Server Core installation)",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "6.2.9200.25368",
                "status": "affected",
                "version": "6.2.9200.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2012 R2",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "6.3.9600.22470",
                "status": "affected",
                "version": "6.3.9600.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2012 R2 (Server Core installation)",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "6.3.9600.22470",
                "status": "affected",
                "version": "6.3.9600.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2016",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.14393.7876",
                "status": "affected",
                "version": "10.0.14393.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2016 (Server Core installation)",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.14393.7876",
                "status": "affected",
                "version": "10.0.14393.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2019",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.17763.7009",
                "status": "affected",
                "version": "10.0.17763.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2019 (Server Core installation)",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.17763.7009",
                "status": "affected",
                "version": "10.0.17763.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2022",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.20348.3328",
                "status": "affected",
                "version": "10.0.20348.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2022, 23H2 Edition (Server Core installation)",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.25398.1486",
                "status": "affected",
                "version": "10.0.25398.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2025",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.26100.3476",
                "status": "affected",
                "version": "10.0.26100.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2025 (Server Core installation)",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.26100.3476",
                "status": "affected",
                "version": "10.0.26100.0",
                "versionType": "custom"
              }
            ]
          }
        ],
        "source": "secure@microsoft.com"
      }
    ],
    "cisaActionDue": "2025-04-01",
    "cisaExploitAdd": "2025-03-11",
    "cisaRequiredAction": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
    "cisaVulnerabilityName": "Microsoft Windows NTFS Heap-Based Buffer Overflow Vulnerability",
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:o:microsoft:windows_10_1507:*:*:*:*:*:*:x64:*",
                "matchCriteriaId": "6997DE6E-CBAD-4690-A68C-8F10E477DCC2",
                "versionEndExcluding": "10.0.10240.20947",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_10_1507:*:*:*:*:*:*:x86:*",
                "matchCriteriaId": "3CBCF6D9-5085-473C-82F5-98BC246A9C4C",
                "versionEndExcluding": "10.0.10240.20947",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x64:*",
                "matchCriteriaId": "0CF0E174-4692-4AA3-B72E-12E73A1BDBE5",
                "versionEndExcluding": "10.0.14393.7876",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x86:*",
                "matchCriteriaId": "340EF5F8-D4F5-4AD8-9D80-1DEC2F376BE5",
                "versionEndExcluding": "10.0.14393.7876",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x64:*",
                "matchCriteriaId": "67C8DCD7-90C4-431F-BD03-FDFDE170E748",
                "versionEndExcluding": "10.0.17763.7009",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x86:*",
                "matchCriteriaId": "05169574-28AB-4E42-B3DE-710574BB1AD3",
                "versionEndExcluding": "10.0.17763.7009",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:arm64:*",
                "matchCriteriaId": "714C0D5E-BE31-45AB-A729-FF55DE59F593",
                "versionEndExcluding": "10.0.19044.5608",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:x64:*",
                "matchCriteriaId": "0C8B2D45-7059-4FA0-A46C-64A171D287DA",
                "versionEndExcluding": "10.0.19044.5608",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:x86:*",
                "matchCriteriaId": "5569800D-B907-47CC-86D2-EC0118157916",
                "versionEndExcluding": "10.0.19044.5608",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:arm64:*",
                "matchCriteriaId": "A84E706C-3A65-4920-8F80-2A684D3CB110",
                "versionEndExcluding": "10.0.19045.5608",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:x64:*",
                "matchCriteriaId": "ED157557-37C1-4802-8746-B87120BA16FA",
                "versionEndExcluding": "10.0.19045.5608",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:x86:*",
                "matchCriteriaId": "BE8F0EF2-EED3-4791-AE26-D24D97B673D6",
                "versionEndExcluding": "10.0.19045.5608",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_11_22h2:*:*:*:*:*:*:arm64:*",
                "matchCriteriaId": "C8949B3E-5847-42F8-A15A-D7515F0EE305",
                "versionEndExcluding": "10.0.22621.5039",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_11_22h2:*:*:*:*:*:*:x64:*",
                "matchCriteriaId": "84D4F97D-3BA2-4B7A-B650-5772DE49CE97",
                "versionEndExcluding": "10.0.22621.5039",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:arm64:*",
                "matchCriteriaId": "82807292-1736-4453-B805-3D471BF94A35",
                "versionEndExcluding": "10.0.22631.5039",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:x64:*",
                "matchCriteriaId": "E19130AD-ECD6-4FC4-B2C8-AB058BDEF928",
                "versionEndExcluding": "10.0.22631.5039",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:arm64:*",
                "matchCriteriaId": "B7ADF37E-1DD3-4539-8922-1E059955FEF1",
                "versionEndExcluding": "10.0.26100.3403",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:x64:*",
                "matchCriteriaId": "E0A74D52-ABC0-4733-B892-F8688B6AEBA7",
                "versionEndExcluding": "10.0.26100.3403",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_server_2008:-:sp2:*:*:*:*:x64:*",
                "matchCriteriaId": "2127D10C-B6F3-4C1D-B9AA-5D78513CC996",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_server_2008:-:sp2:*:*:*:*:x86:*",
                "matchCriteriaId": "AB425562-C0A0-452E-AABE-F70522F15E1A",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:x64:*",
                "matchCriteriaId": "AF07A81D-12E5-4B1D-BFF9-C8D08C32FF4F",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*",
                "matchCriteriaId": "A7DF96F8-BA6A-4780-9CA3-F719B3F81074",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*",
                "matchCriteriaId": "DB18C4CE-5917-401E-ACF7-2747084FD36E",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_server_2016:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "C7610CDB-A02B-4C62-B17F-6DCE2B3DE4F0",
                "versionEndExcluding": "10.0.14393.7876",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_server_2019:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "D271422D-A29F-4DBF-BF72-BCD90E393A5A",
                "versionEndExcluding": "10.0.17763.7009",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_server_2022:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "AAACC9C4-DDC5-4059-AFE3-A49DB2347A86",
                "versionEndExcluding": "10.0.20348.3270",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_server_2022_23h2:*:*:*:*:*:*:x64:*",
                "matchCriteriaId": "96046A7B-76A1-4DCF-AEA5-25344D37E492",
                "versionEndExcluding": "10.0.25398.1486",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:x64:*",
                "matchCriteriaId": "CE542697-31D8-4EC2-8135-F0468431FD19",
                "versionEndExcluding": "10.0.26100.3403",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally."
      },
      {
        "lang": "es",
        "value": "El desbordamiento del búfer basado en montón en Windows NTFS permite que un atacante no autorizado ejecute código localmente."
      }
    ],
    "id": "CVE-2025-24993",
    "lastModified": "2026-09-24T13:10:00.320",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "HIGH",
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 1.8,
          "impactScore": 5.9,
          "source": "secure@microsoft.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-24993",
            "options": [
              {
                "exploitation": "active"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2025-03-14T03:55:33.583406Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2025-03-11T17:16:35.797",
    "references": [
      {
        "source": "secure@microsoft.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-24993"
      },
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "tags": [
          "US Government Resource"
        ],
        "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-24993"
      }
    ],
    "sourceIdentifier": "secure@microsoft.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-122"
          }
        ],
        "source": "secure@microsoft.com",
        "type": "Secondary"
      }
    ]
  }
}
—
CVSS
cvss
NVD7.8
receipt
Source
NVD
Its words
7.8
Read by
field:cve.metrics.cvssMetricV31[type=Primary].cvssData.baseScore || field:cve.metrics.cvssMetricV31[].cvssData.baseScore
Said since
2026-09-29 09:45 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "platforms": [
              "32-bit Systems",
              "x64-based Systems"
            ],
            "product": "Windows 10 Version 1507",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.10240.20947",
                "status": "affected",
                "version": "10.0.10240.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "32-bit Systems",
              "x64-based Systems"
            ],
            "product": "Windows 10 Version 1607",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.14393.7876",
                "status": "affected",
                "version": "10.0.14393.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "32-bit Systems",
              "x64-based Systems"
            ],
            "product": "Windows 10 Version 1809",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.17763.7009",
                "status": "affected",
                "version": "10.0.17763.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "32-bit Systems",
              "ARM64-based Systems",
              "x64-based Systems"
            ],
            "product": "Windows 10 Version 21H2",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.19044.5608",
                "status": "affected",
                "version": "10.0.19044.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "32-bit Systems",
              "ARM64-based Systems",
              "x64-based Systems"
            ],
            "product": "Windows 10 Version 22H2",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.19045.5608",
                "status": "affected",
                "version": "10.0.19045.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "ARM64-based Systems",
              "x64-based Systems"
            ],
            "product": "Windows 11 version 22H2",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.22621.5039",
                "status": "affected",
                "version": "10.0.22621.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "ARM64-based Systems"
            ],
            "product": "Windows 11 version 22H3",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.22631.5039",
                "status": "affected",
                "version": "10.0.22631.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows 11 Version 23H2",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.22631.5039",
                "status": "affected",
                "version": "10.0.22631.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "ARM64-based Systems",
              "x64-based Systems"
            ],
            "product": "Windows 11 Version 24H2",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.26100.3476",
                "status": "affected",
                "version": "10.0.26100.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2008 R2 Service Pack 1",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "6.1.7601.27618",
                "status": "affected",
                "version": "6.1.7601.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2008 R2 Service Pack 1 (Server Core installation)",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "6.1.7601.27618",
                "status": "affected",
                "version": "6.1.7601.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "32-bit Systems",
              "x64-based Systems"
            ],
            "product": "Windows Server 2008 Service Pack 2",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "6.0.6003.23168",
                "status": "affected",
                "version": "6.0.6003.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "32-bit Systems",
              "x64-based Systems"
            ],
            "product": "Windows Server 2008 Service Pack 2 (Server Core installation)",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "6.0.6003.23168",
                "status": "affected",
                "version": "6.0.6003.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2012",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "6.2.9200.25368",
                "status": "affected",
                "version": "6.2.9200.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2012 (Server Core installation)",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "6.2.9200.25368",
                "status": "affected",
                "version": "6.2.9200.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2012 R2",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "6.3.9600.22470",
                "status": "affected",
                "version": "6.3.9600.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2012 R2 (Server Core installation)",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "6.3.9600.22470",
                "status": "affected",
                "version": "6.3.9600.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2016",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.14393.7876",
                "status": "affected",
                "version": "10.0.14393.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2016 (Server Core installation)",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.14393.7876",
                "status": "affected",
                "version": "10.0.14393.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2019",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.17763.7009",
                "status": "affected",
                "version": "10.0.17763.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2019 (Server Core installation)",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.17763.7009",
                "status": "affected",
                "version": "10.0.17763.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2022",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.20348.3328",
                "status": "affected",
                "version": "10.0.20348.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2022, 23H2 Edition (Server Core installation)",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.25398.1486",
                "status": "affected",
                "version": "10.0.25398.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2025",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.26100.3476",
                "status": "affected",
                "version": "10.0.26100.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2025 (Server Core installation)",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.26100.3476",
                "status": "affected",
                "version": "10.0.26100.0",
                "versionType": "custom"
              }
            ]
          }
        ],
        "source": "secure@microsoft.com"
      }
    ],
    "cisaActionDue": "2025-04-01",
    "cisaExploitAdd": "2025-03-11",
    "cisaRequiredAction": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
    "cisaVulnerabilityName": "Microsoft Windows NTFS Heap-Based Buffer Overflow Vulnerability",
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:o:microsoft:windows_10_1507:*:*:*:*:*:*:x64:*",
                "matchCriteriaId": "6997DE6E-CBAD-4690-A68C-8F10E477DCC2",
                "versionEndExcluding": "10.0.10240.20947",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_10_1507:*:*:*:*:*:*:x86:*",
                "matchCriteriaId": "3CBCF6D9-5085-473C-82F5-98BC246A9C4C",
                "versionEndExcluding": "10.0.10240.20947",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x64:*",
                "matchCriteriaId": "0CF0E174-4692-4AA3-B72E-12E73A1BDBE5",
                "versionEndExcluding": "10.0.14393.7876",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x86:*",
                "matchCriteriaId": "340EF5F8-D4F5-4AD8-9D80-1DEC2F376BE5",
                "versionEndExcluding": "10.0.14393.7876",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x64:*",
                "matchCriteriaId": "67C8DCD7-90C4-431F-BD03-FDFDE170E748",
                "versionEndExcluding": "10.0.17763.7009",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x86:*",
                "matchCriteriaId": "05169574-28AB-4E42-B3DE-710574BB1AD3",
                "versionEndExcluding": "10.0.17763.7009",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:arm64:*",
                "matchCriteriaId": "714C0D5E-BE31-45AB-A729-FF55DE59F593",
                "versionEndExcluding": "10.0.19044.5608",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:x64:*",
                "matchCriteriaId": "0C8B2D45-7059-4FA0-A46C-64A171D287DA",
                "versionEndExcluding": "10.0.19044.5608",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:x86:*",
                "matchCriteriaId": "5569800D-B907-47CC-86D2-EC0118157916",
                "versionEndExcluding": "10.0.19044.5608",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:arm64:*",
                "matchCriteriaId": "A84E706C-3A65-4920-8F80-2A684D3CB110",
                "versionEndExcluding": "10.0.19045.5608",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:x64:*",
                "matchCriteriaId": "ED157557-37C1-4802-8746-B87120BA16FA",
                "versionEndExcluding": "10.0.19045.5608",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:x86:*",
                "matchCriteriaId": "BE8F0EF2-EED3-4791-AE26-D24D97B673D6",
                "versionEndExcluding": "10.0.19045.5608",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_11_22h2:*:*:*:*:*:*:arm64:*",
                "matchCriteriaId": "C8949B3E-5847-42F8-A15A-D7515F0EE305",
                "versionEndExcluding": "10.0.22621.5039",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_11_22h2:*:*:*:*:*:*:x64:*",
                "matchCriteriaId": "84D4F97D-3BA2-4B7A-B650-5772DE49CE97",
                "versionEndExcluding": "10.0.22621.5039",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:arm64:*",
                "matchCriteriaId": "82807292-1736-4453-B805-3D471BF94A35",
                "versionEndExcluding": "10.0.22631.5039",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:x64:*",
                "matchCriteriaId": "E19130AD-ECD6-4FC4-B2C8-AB058BDEF928",
                "versionEndExcluding": "10.0.22631.5039",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:arm64:*",
                "matchCriteriaId": "B7ADF37E-1DD3-4539-8922-1E059955FEF1",
                "versionEndExcluding": "10.0.26100.3403",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:x64:*",
                "matchCriteriaId": "E0A74D52-ABC0-4733-B892-F8688B6AEBA7",
                "versionEndExcluding": "10.0.26100.3403",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_server_2008:-:sp2:*:*:*:*:x64:*",
                "matchCriteriaId": "2127D10C-B6F3-4C1D-B9AA-5D78513CC996",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_server_2008:-:sp2:*:*:*:*:x86:*",
                "matchCriteriaId": "AB425562-C0A0-452E-AABE-F70522F15E1A",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:x64:*",
                "matchCriteriaId": "AF07A81D-12E5-4B1D-BFF9-C8D08C32FF4F",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*",
                "matchCriteriaId": "A7DF96F8-BA6A-4780-9CA3-F719B3F81074",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*",
                "matchCriteriaId": "DB18C4CE-5917-401E-ACF7-2747084FD36E",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_server_2016:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "C7610CDB-A02B-4C62-B17F-6DCE2B3DE4F0",
                "versionEndExcluding": "10.0.14393.7876",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_server_2019:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "D271422D-A29F-4DBF-BF72-BCD90E393A5A",
                "versionEndExcluding": "10.0.17763.7009",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_server_2022:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "AAACC9C4-DDC5-4059-AFE3-A49DB2347A86",
                "versionEndExcluding": "10.0.20348.3270",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_server_2022_23h2:*:*:*:*:*:*:x64:*",
                "matchCriteriaId": "96046A7B-76A1-4DCF-AEA5-25344D37E492",
                "versionEndExcluding": "10.0.25398.1486",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:x64:*",
                "matchCriteriaId": "CE542697-31D8-4EC2-8135-F0468431FD19",
                "versionEndExcluding": "10.0.26100.3403",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally."
      },
      {
        "lang": "es",
        "value": "El desbordamiento del búfer basado en montón en Windows NTFS permite que un atacante no autorizado ejecute código localmente."
      }
    ],
    "id": "CVE-2025-24993",
    "lastModified": "2026-09-24T13:10:00.320",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "HIGH",
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 1.8,
          "impactScore": 5.9,
          "source": "secure@microsoft.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-24993",
            "options": [
              {
                "exploitation": "active"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2025-03-14T03:55:33.583406Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2025-03-11T17:16:35.797",
    "references": [
      {
        "source": "secure@microsoft.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-24993"
      },
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "tags": [
          "US Government Resource"
        ],
        "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-24993"
      }
    ],
    "sourceIdentifier": "secure@microsoft.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-122"
          }
        ],
        "source": "secure@microsoft.com",
        "type": "Secondary"
      }
    ]
  }
}
—
CVSS vector
cvss_vector
NVDCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
receipt
Source
NVD
Its words
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Read by
field:cve.metrics.cvssMetricV31[type=Primary].cvssData.vectorString || field:cve.metrics.cvssMetricV31[].cvssData.vectorString
Said since
2026-10-06 11:54 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 11:54 UTCCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "platforms": [
              "32-bit Systems",
              "x64-based Systems"
            ],
            "product": "Windows 10 Version 1507",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.10240.20947",
                "status": "affected",
                "version": "10.0.10240.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "32-bit Systems",
              "x64-based Systems"
            ],
            "product": "Windows 10 Version 1607",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.14393.7876",
                "status": "affected",
                "version": "10.0.14393.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "32-bit Systems",
              "x64-based Systems"
            ],
            "product": "Windows 10 Version 1809",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.17763.7009",
                "status": "affected",
                "version": "10.0.17763.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "32-bit Systems",
              "ARM64-based Systems",
              "x64-based Systems"
            ],
            "product": "Windows 10 Version 21H2",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.19044.5608",
                "status": "affected",
                "version": "10.0.19044.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "32-bit Systems",
              "ARM64-based Systems",
              "x64-based Systems"
            ],
            "product": "Windows 10 Version 22H2",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.19045.5608",
                "status": "affected",
                "version": "10.0.19045.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "ARM64-based Systems",
              "x64-based Systems"
            ],
            "product": "Windows 11 version 22H2",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.22621.5039",
                "status": "affected",
                "version": "10.0.22621.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "ARM64-based Systems"
            ],
            "product": "Windows 11 version 22H3",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.22631.5039",
                "status": "affected",
                "version": "10.0.22631.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows 11 Version 23H2",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.22631.5039",
                "status": "affected",
                "version": "10.0.22631.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "ARM64-based Systems",
              "x64-based Systems"
            ],
            "product": "Windows 11 Version 24H2",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.26100.3476",
                "status": "affected",
                "version": "10.0.26100.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2008 R2 Service Pack 1",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "6.1.7601.27618",
                "status": "affected",
                "version": "6.1.7601.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2008 R2 Service Pack 1 (Server Core installation)",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "6.1.7601.27618",
                "status": "affected",
                "version": "6.1.7601.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "32-bit Systems",
              "x64-based Systems"
            ],
            "product": "Windows Server 2008 Service Pack 2",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "6.0.6003.23168",
                "status": "affected",
                "version": "6.0.6003.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "32-bit Systems",
              "x64-based Systems"
            ],
            "product": "Windows Server 2008 Service Pack 2 (Server Core installation)",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "6.0.6003.23168",
                "status": "affected",
                "version": "6.0.6003.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2012",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "6.2.9200.25368",
                "status": "affected",
                "version": "6.2.9200.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2012 (Server Core installation)",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "6.2.9200.25368",
                "status": "affected",
                "version": "6.2.9200.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2012 R2",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "6.3.9600.22470",
                "status": "affected",
                "version": "6.3.9600.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2012 R2 (Server Core installation)",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "6.3.9600.22470",
                "status": "affected",
                "version": "6.3.9600.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2016",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.14393.7876",
                "status": "affected",
                "version": "10.0.14393.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2016 (Server Core installation)",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.14393.7876",
                "status": "affected",
                "version": "10.0.14393.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2019",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.17763.7009",
                "status": "affected",
                "version": "10.0.17763.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2019 (Server Core installation)",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.17763.7009",
                "status": "affected",
                "version": "10.0.17763.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2022",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.20348.3328",
                "status": "affected",
                "version": "10.0.20348.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2022, 23H2 Edition (Server Core installation)",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.25398.1486",
                "status": "affected",
                "version": "10.0.25398.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2025",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.26100.3476",
                "status": "affected",
                "version": "10.0.26100.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2025 (Server Core installation)",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.26100.3476",
                "status": "affected",
                "version": "10.0.26100.0",
                "versionType": "custom"
              }
            ]
          }
        ],
        "source": "secure@microsoft.com"
      }
    ],
    "cisaActionDue": "2025-04-01",
    "cisaExploitAdd": "2025-03-11",
    "cisaRequiredAction": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
    "cisaVulnerabilityName": "Microsoft Windows NTFS Heap-Based Buffer Overflow Vulnerability",
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:o:microsoft:windows_10_1507:*:*:*:*:*:*:x64:*",
                "matchCriteriaId": "6997DE6E-CBAD-4690-A68C-8F10E477DCC2",
                "versionEndExcluding": "10.0.10240.20947",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_10_1507:*:*:*:*:*:*:x86:*",
                "matchCriteriaId": "3CBCF6D9-5085-473C-82F5-98BC246A9C4C",
                "versionEndExcluding": "10.0.10240.20947",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x64:*",
                "matchCriteriaId": "0CF0E174-4692-4AA3-B72E-12E73A1BDBE5",
                "versionEndExcluding": "10.0.14393.7876",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x86:*",
                "matchCriteriaId": "340EF5F8-D4F5-4AD8-9D80-1DEC2F376BE5",
                "versionEndExcluding": "10.0.14393.7876",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x64:*",
                "matchCriteriaId": "67C8DCD7-90C4-431F-BD03-FDFDE170E748",
                "versionEndExcluding": "10.0.17763.7009",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x86:*",
                "matchCriteriaId": "05169574-28AB-4E42-B3DE-710574BB1AD3",
                "versionEndExcluding": "10.0.17763.7009",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:arm64:*",
                "matchCriteriaId": "714C0D5E-BE31-45AB-A729-FF55DE59F593",
                "versionEndExcluding": "10.0.19044.5608",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:x64:*",
                "matchCriteriaId": "0C8B2D45-7059-4FA0-A46C-64A171D287DA",
                "versionEndExcluding": "10.0.19044.5608",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:x86:*",
                "matchCriteriaId": "5569800D-B907-47CC-86D2-EC0118157916",
                "versionEndExcluding": "10.0.19044.5608",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:arm64:*",
                "matchCriteriaId": "A84E706C-3A65-4920-8F80-2A684D3CB110",
                "versionEndExcluding": "10.0.19045.5608",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:x64:*",
                "matchCriteriaId": "ED157557-37C1-4802-8746-B87120BA16FA",
                "versionEndExcluding": "10.0.19045.5608",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:x86:*",
                "matchCriteriaId": "BE8F0EF2-EED3-4791-AE26-D24D97B673D6",
                "versionEndExcluding": "10.0.19045.5608",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_11_22h2:*:*:*:*:*:*:arm64:*",
                "matchCriteriaId": "C8949B3E-5847-42F8-A15A-D7515F0EE305",
                "versionEndExcluding": "10.0.22621.5039",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_11_22h2:*:*:*:*:*:*:x64:*",
                "matchCriteriaId": "84D4F97D-3BA2-4B7A-B650-5772DE49CE97",
                "versionEndExcluding": "10.0.22621.5039",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:arm64:*",
                "matchCriteriaId": "82807292-1736-4453-B805-3D471BF94A35",
                "versionEndExcluding": "10.0.22631.5039",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:x64:*",
                "matchCriteriaId": "E19130AD-ECD6-4FC4-B2C8-AB058BDEF928",
                "versionEndExcluding": "10.0.22631.5039",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:arm64:*",
                "matchCriteriaId": "B7ADF37E-1DD3-4539-8922-1E059955FEF1",
                "versionEndExcluding": "10.0.26100.3403",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:x64:*",
                "matchCriteriaId": "E0A74D52-ABC0-4733-B892-F8688B6AEBA7",
                "versionEndExcluding": "10.0.26100.3403",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_server_2008:-:sp2:*:*:*:*:x64:*",
                "matchCriteriaId": "2127D10C-B6F3-4C1D-B9AA-5D78513CC996",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_server_2008:-:sp2:*:*:*:*:x86:*",
                "matchCriteriaId": "AB425562-C0A0-452E-AABE-F70522F15E1A",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:x64:*",
                "matchCriteriaId": "AF07A81D-12E5-4B1D-BFF9-C8D08C32FF4F",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*",
                "matchCriteriaId": "A7DF96F8-BA6A-4780-9CA3-F719B3F81074",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*",
                "matchCriteriaId": "DB18C4CE-5917-401E-ACF7-2747084FD36E",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_server_2016:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "C7610CDB-A02B-4C62-B17F-6DCE2B3DE4F0",
                "versionEndExcluding": "10.0.14393.7876",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_server_2019:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "D271422D-A29F-4DBF-BF72-BCD90E393A5A",
                "versionEndExcluding": "10.0.17763.7009",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_server_2022:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "AAACC9C4-DDC5-4059-AFE3-A49DB2347A86",
                "versionEndExcluding": "10.0.20348.3270",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_server_2022_23h2:*:*:*:*:*:*:x64:*",
                "matchCriteriaId": "96046A7B-76A1-4DCF-AEA5-25344D37E492",
                "versionEndExcluding": "10.0.25398.1486",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:x64:*",
                "matchCriteriaId": "CE542697-31D8-4EC2-8135-F0468431FD19",
                "versionEndExcluding": "10.0.26100.3403",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally."
      },
      {
        "lang": "es",
        "value": "El desbordamiento del búfer basado en montón en Windows NTFS permite que un atacante no autorizado ejecute código localmente."
      }
    ],
    "id": "CVE-2025-24993",
    "lastModified": "2026-09-24T13:10:00.320",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "HIGH",
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 1.8,
          "impactScore": 5.9,
          "source": "secure@microsoft.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-24993",
            "options": [
              {
                "exploitation": "active"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2025-03-14T03:55:33.583406Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2025-03-11T17:16:35.797",
    "references": [
      {
        "source": "secure@microsoft.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-24993"
      },
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "tags": [
          "US Government Resource"
        ],
        "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-24993"
      }
    ],
    "sourceIdentifier": "secure@microsoft.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-122"
          }
        ],
        "source": "secure@microsoft.com",
        "type": "Secondary"
      }
    ]
  }
}
—
CWE
cwe
CISA Known Exploited VulnerabilitiesCWE-122
receipt
Source
CISA Known Exploited Vulnerabilities
Its words
CWE-122
Read by
field:cwes
Said since
2026-10-06 12:19 UTC
Last answered
2026-10-06 17:36 UTC
2026-10-06 12:19 UTCCWE-122
2026-09-28 11:44 UTC—
What the source handed over
{
  "cveID": "CVE-2025-24993",
  "cwes": "CWE-122",
  "dateAdded": "2025-03-11",
  "dueDate": "2025-04-01",
  "forensicTriage": "No",
  "knownRansomwareCampaignUse": "Unknown",
  "notes": "https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2025-24993 ; https://nvd.nist.gov/vuln/detail/CVE-2025-24993",
  "product": "Windows",
  "requiredAction": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
  "shortDescription": "Microsoft Windows New Technology File System (NTFS) contains a heap-based buffer overflow vulnerability that allows an unauthorized attacker to execute code locally.",
  "vendorProject": "Microsoft",
  "vulnerabilityName": "Microsoft Windows NTFS Heap-Based Buffer Overflow Vulnerability"
}
—
CWE
cwe
NVDCWE-122
receipt
Source
NVD
Its words
CWE-122
Read by
field:cve.weaknesses[].description[].value
Said since
2026-10-06 11:54 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 11:54 UTCCWE-122
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "platforms": [
              "32-bit Systems",
              "x64-based Systems"
            ],
            "product": "Windows 10 Version 1507",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.10240.20947",
                "status": "affected",
                "version": "10.0.10240.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "32-bit Systems",
              "x64-based Systems"
            ],
            "product": "Windows 10 Version 1607",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.14393.7876",
                "status": "affected",
                "version": "10.0.14393.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "32-bit Systems",
              "x64-based Systems"
            ],
            "product": "Windows 10 Version 1809",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.17763.7009",
                "status": "affected",
                "version": "10.0.17763.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "32-bit Systems",
              "ARM64-based Systems",
              "x64-based Systems"
            ],
            "product": "Windows 10 Version 21H2",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.19044.5608",
                "status": "affected",
                "version": "10.0.19044.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "32-bit Systems",
              "ARM64-based Systems",
              "x64-based Systems"
            ],
            "product": "Windows 10 Version 22H2",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.19045.5608",
                "status": "affected",
                "version": "10.0.19045.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "ARM64-based Systems",
              "x64-based Systems"
            ],
            "product": "Windows 11 version 22H2",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.22621.5039",
                "status": "affected",
                "version": "10.0.22621.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "ARM64-based Systems"
            ],
            "product": "Windows 11 version 22H3",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.22631.5039",
                "status": "affected",
                "version": "10.0.22631.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows 11 Version 23H2",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.22631.5039",
                "status": "affected",
                "version": "10.0.22631.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "ARM64-based Systems",
              "x64-based Systems"
            ],
            "product": "Windows 11 Version 24H2",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.26100.3476",
                "status": "affected",
                "version": "10.0.26100.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2008 R2 Service Pack 1",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "6.1.7601.27618",
                "status": "affected",
                "version": "6.1.7601.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2008 R2 Service Pack 1 (Server Core installation)",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "6.1.7601.27618",
                "status": "affected",
                "version": "6.1.7601.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "32-bit Systems",
              "x64-based Systems"
            ],
            "product": "Windows Server 2008 Service Pack 2",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "6.0.6003.23168",
                "status": "affected",
                "version": "6.0.6003.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "32-bit Systems",
              "x64-based Systems"
            ],
            "product": "Windows Server 2008 Service Pack 2 (Server Core installation)",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "6.0.6003.23168",
                "status": "affected",
                "version": "6.0.6003.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2012",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "6.2.9200.25368",
                "status": "affected",
                "version": "6.2.9200.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2012 (Server Core installation)",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "6.2.9200.25368",
                "status": "affected",
                "version": "6.2.9200.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2012 R2",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "6.3.9600.22470",
                "status": "affected",
                "version": "6.3.9600.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2012 R2 (Server Core installation)",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "6.3.9600.22470",
                "status": "affected",
                "version": "6.3.9600.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2016",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.14393.7876",
                "status": "affected",
                "version": "10.0.14393.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2016 (Server Core installation)",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.14393.7876",
                "status": "affected",
                "version": "10.0.14393.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2019",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.17763.7009",
                "status": "affected",
                "version": "10.0.17763.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2019 (Server Core installation)",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.17763.7009",
                "status": "affected",
                "version": "10.0.17763.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2022",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.20348.3328",
                "status": "affected",
                "version": "10.0.20348.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2022, 23H2 Edition (Server Core installation)",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.25398.1486",
                "status": "affected",
                "version": "10.0.25398.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2025",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.26100.3476",
                "status": "affected",
                "version": "10.0.26100.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2025 (Server Core installation)",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.26100.3476",
                "status": "affected",
                "version": "10.0.26100.0",
                "versionType": "custom"
              }
            ]
          }
        ],
        "source": "secure@microsoft.com"
      }
    ],
    "cisaActionDue": "2025-04-01",
    "cisaExploitAdd": "2025-03-11",
    "cisaRequiredAction": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
    "cisaVulnerabilityName": "Microsoft Windows NTFS Heap-Based Buffer Overflow Vulnerability",
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:o:microsoft:windows_10_1507:*:*:*:*:*:*:x64:*",
                "matchCriteriaId": "6997DE6E-CBAD-4690-A68C-8F10E477DCC2",
                "versionEndExcluding": "10.0.10240.20947",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_10_1507:*:*:*:*:*:*:x86:*",
                "matchCriteriaId": "3CBCF6D9-5085-473C-82F5-98BC246A9C4C",
                "versionEndExcluding": "10.0.10240.20947",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x64:*",
                "matchCriteriaId": "0CF0E174-4692-4AA3-B72E-12E73A1BDBE5",
                "versionEndExcluding": "10.0.14393.7876",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x86:*",
                "matchCriteriaId": "340EF5F8-D4F5-4AD8-9D80-1DEC2F376BE5",
                "versionEndExcluding": "10.0.14393.7876",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x64:*",
                "matchCriteriaId": "67C8DCD7-90C4-431F-BD03-FDFDE170E748",
                "versionEndExcluding": "10.0.17763.7009",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x86:*",
                "matchCriteriaId": "05169574-28AB-4E42-B3DE-710574BB1AD3",
                "versionEndExcluding": "10.0.17763.7009",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:arm64:*",
                "matchCriteriaId": "714C0D5E-BE31-45AB-A729-FF55DE59F593",
                "versionEndExcluding": "10.0.19044.5608",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:x64:*",
                "matchCriteriaId": "0C8B2D45-7059-4FA0-A46C-64A171D287DA",
                "versionEndExcluding": "10.0.19044.5608",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:x86:*",
                "matchCriteriaId": "5569800D-B907-47CC-86D2-EC0118157916",
                "versionEndExcluding": "10.0.19044.5608",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:arm64:*",
                "matchCriteriaId": "A84E706C-3A65-4920-8F80-2A684D3CB110",
                "versionEndExcluding": "10.0.19045.5608",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:x64:*",
                "matchCriteriaId": "ED157557-37C1-4802-8746-B87120BA16FA",
                "versionEndExcluding": "10.0.19045.5608",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:x86:*",
                "matchCriteriaId": "BE8F0EF2-EED3-4791-AE26-D24D97B673D6",
                "versionEndExcluding": "10.0.19045.5608",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_11_22h2:*:*:*:*:*:*:arm64:*",
                "matchCriteriaId": "C8949B3E-5847-42F8-A15A-D7515F0EE305",
                "versionEndExcluding": "10.0.22621.5039",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_11_22h2:*:*:*:*:*:*:x64:*",
                "matchCriteriaId": "84D4F97D-3BA2-4B7A-B650-5772DE49CE97",
                "versionEndExcluding": "10.0.22621.5039",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:arm64:*",
                "matchCriteriaId": "82807292-1736-4453-B805-3D471BF94A35",
                "versionEndExcluding": "10.0.22631.5039",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:x64:*",
                "matchCriteriaId": "E19130AD-ECD6-4FC4-B2C8-AB058BDEF928",
                "versionEndExcluding": "10.0.22631.5039",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:arm64:*",
                "matchCriteriaId": "B7ADF37E-1DD3-4539-8922-1E059955FEF1",
                "versionEndExcluding": "10.0.26100.3403",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:x64:*",
                "matchCriteriaId": "E0A74D52-ABC0-4733-B892-F8688B6AEBA7",
                "versionEndExcluding": "10.0.26100.3403",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_server_2008:-:sp2:*:*:*:*:x64:*",
                "matchCriteriaId": "2127D10C-B6F3-4C1D-B9AA-5D78513CC996",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_server_2008:-:sp2:*:*:*:*:x86:*",
                "matchCriteriaId": "AB425562-C0A0-452E-AABE-F70522F15E1A",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:x64:*",
                "matchCriteriaId": "AF07A81D-12E5-4B1D-BFF9-C8D08C32FF4F",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*",
                "matchCriteriaId": "A7DF96F8-BA6A-4780-9CA3-F719B3F81074",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*",
                "matchCriteriaId": "DB18C4CE-5917-401E-ACF7-2747084FD36E",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_server_2016:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "C7610CDB-A02B-4C62-B17F-6DCE2B3DE4F0",
                "versionEndExcluding": "10.0.14393.7876",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_server_2019:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "D271422D-A29F-4DBF-BF72-BCD90E393A5A",
                "versionEndExcluding": "10.0.17763.7009",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_server_2022:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "AAACC9C4-DDC5-4059-AFE3-A49DB2347A86",
                "versionEndExcluding": "10.0.20348.3270",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_server_2022_23h2:*:*:*:*:*:*:x64:*",
                "matchCriteriaId": "96046A7B-76A1-4DCF-AEA5-25344D37E492",
                "versionEndExcluding": "10.0.25398.1486",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:x64:*",
                "matchCriteriaId": "CE542697-31D8-4EC2-8135-F0468431FD19",
                "versionEndExcluding": "10.0.26100.3403",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally."
      },
      {
        "lang": "es",
        "value": "El desbordamiento del búfer basado en montón en Windows NTFS permite que un atacante no autorizado ejecute código localmente."
      }
    ],
    "id": "CVE-2025-24993",
    "lastModified": "2026-09-24T13:10:00.320",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "HIGH",
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 1.8,
          "impactScore": 5.9,
          "source": "secure@microsoft.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-24993",
            "options": [
              {
                "exploitation": "active"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2025-03-14T03:55:33.583406Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2025-03-11T17:16:35.797",
    "references": [
      {
        "source": "secure@microsoft.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-24993"
      },
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "tags": [
          "US Government Resource"
        ],
        "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-24993"
      }
    ],
    "sourceIdentifier": "secure@microsoft.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-122"
          }
        ],
        "source": "secure@microsoft.com",
        "type": "Secondary"
      }
    ]
  }
}
—
CWES
cwes
CISA Known Exploited VulnerabilitiesCWE-122
receipt
Source
CISA Known Exploited Vulnerabilities
Its words
CWE-122
Read by
field:cwes
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-06 17:36 UTC
What the source handed over
{
  "cveID": "CVE-2025-24993",
  "cwes": "CWE-122",
  "dateAdded": "2025-03-11",
  "dueDate": "2025-04-01",
  "forensicTriage": "No",
  "knownRansomwareCampaignUse": "Unknown",
  "notes": "https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2025-24993 ; https://nvd.nist.gov/vuln/detail/CVE-2025-24993",
  "product": "Windows",
  "requiredAction": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
  "shortDescription": "Microsoft Windows New Technology File System (NTFS) contains a heap-based buffer overflow vulnerability that allows an unauthorized attacker to execute code locally.",
  "vendorProject": "Microsoft",
  "vulnerabilityName": "Microsoft Windows NTFS Heap-Based Buffer Overflow Vulnerability"
}
—
Due date
due_date
CISA Known Exploited Vulnerabilities2025-04-01
receipt
Source
CISA Known Exploited Vulnerabilities
Its words
2025-04-01
Read by
field:dueDate
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-06 17:36 UTC
What the source handed over
{
  "cveID": "CVE-2025-24993",
  "cwes": "CWE-122",
  "dateAdded": "2025-03-11",
  "dueDate": "2025-04-01",
  "forensicTriage": "No",
  "knownRansomwareCampaignUse": "Unknown",
  "notes": "https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2025-24993 ; https://nvd.nist.gov/vuln/detail/CVE-2025-24993",
  "product": "Windows",
  "requiredAction": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
  "shortDescription": "Microsoft Windows New Technology File System (NTFS) contains a heap-based buffer overflow vulnerability that allows an unauthorized attacker to execute code locally.",
  "vendorProject": "Microsoft",
  "vulnerabilityName": "Microsoft Windows NTFS Heap-Based Buffer Overflow Vulnerability"
}
—
Exploitation
exploitation
NVDactive
Reliable evidence that it is exploited in the wild.
receipt
Source
NVD
Its words
active
Read by
field:cve.metrics.ssvcV203[].ssvcData.options[].exploitation
Said since
2026-10-06 11:54 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 11:54 UTCactive
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "platforms": [
              "32-bit Systems",
              "x64-based Systems"
            ],
            "product": "Windows 10 Version 1507",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.10240.20947",
                "status": "affected",
                "version": "10.0.10240.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "32-bit Systems",
              "x64-based Systems"
            ],
            "product": "Windows 10 Version 1607",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.14393.7876",
                "status": "affected",
                "version": "10.0.14393.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "32-bit Systems",
              "x64-based Systems"
            ],
            "product": "Windows 10 Version 1809",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.17763.7009",
                "status": "affected",
                "version": "10.0.17763.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "32-bit Systems",
              "ARM64-based Systems",
              "x64-based Systems"
            ],
            "product": "Windows 10 Version 21H2",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.19044.5608",
                "status": "affected",
                "version": "10.0.19044.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "32-bit Systems",
              "ARM64-based Systems",
              "x64-based Systems"
            ],
            "product": "Windows 10 Version 22H2",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.19045.5608",
                "status": "affected",
                "version": "10.0.19045.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "ARM64-based Systems",
              "x64-based Systems"
            ],
            "product": "Windows 11 version 22H2",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.22621.5039",
                "status": "affected",
                "version": "10.0.22621.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "ARM64-based Systems"
            ],
            "product": "Windows 11 version 22H3",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.22631.5039",
                "status": "affected",
                "version": "10.0.22631.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows 11 Version 23H2",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.22631.5039",
                "status": "affected",
                "version": "10.0.22631.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "ARM64-based Systems",
              "x64-based Systems"
            ],
            "product": "Windows 11 Version 24H2",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.26100.3476",
                "status": "affected",
                "version": "10.0.26100.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2008 R2 Service Pack 1",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "6.1.7601.27618",
                "status": "affected",
                "version": "6.1.7601.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2008 R2 Service Pack 1 (Server Core installation)",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "6.1.7601.27618",
                "status": "affected",
                "version": "6.1.7601.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "32-bit Systems",
              "x64-based Systems"
            ],
            "product": "Windows Server 2008 Service Pack 2",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "6.0.6003.23168",
                "status": "affected",
                "version": "6.0.6003.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "32-bit Systems",
              "x64-based Systems"
            ],
            "product": "Windows Server 2008 Service Pack 2 (Server Core installation)",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "6.0.6003.23168",
                "status": "affected",
                "version": "6.0.6003.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2012",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "6.2.9200.25368",
                "status": "affected",
                "version": "6.2.9200.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2012 (Server Core installation)",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "6.2.9200.25368",
                "status": "affected",
                "version": "6.2.9200.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2012 R2",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "6.3.9600.22470",
                "status": "affected",
                "version": "6.3.9600.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2012 R2 (Server Core installation)",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "6.3.9600.22470",
                "status": "affected",
                "version": "6.3.9600.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2016",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.14393.7876",
                "status": "affected",
                "version": "10.0.14393.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2016 (Server Core installation)",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.14393.7876",
                "status": "affected",
                "version": "10.0.14393.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2019",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.17763.7009",
                "status": "affected",
                "version": "10.0.17763.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2019 (Server Core installation)",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.17763.7009",
                "status": "affected",
                "version": "10.0.17763.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2022",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.20348.3328",
                "status": "affected",
                "version": "10.0.20348.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2022, 23H2 Edition (Server Core installation)",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.25398.1486",
                "status": "affected",
                "version": "10.0.25398.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2025",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.26100.3476",
                "status": "affected",
                "version": "10.0.26100.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2025 (Server Core installation)",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.26100.3476",
                "status": "affected",
                "version": "10.0.26100.0",
                "versionType": "custom"
              }
            ]
          }
        ],
        "source": "secure@microsoft.com"
      }
    ],
    "cisaActionDue": "2025-04-01",
    "cisaExploitAdd": "2025-03-11",
    "cisaRequiredAction": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
    "cisaVulnerabilityName": "Microsoft Windows NTFS Heap-Based Buffer Overflow Vulnerability",
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:o:microsoft:windows_10_1507:*:*:*:*:*:*:x64:*",
                "matchCriteriaId": "6997DE6E-CBAD-4690-A68C-8F10E477DCC2",
                "versionEndExcluding": "10.0.10240.20947",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_10_1507:*:*:*:*:*:*:x86:*",
                "matchCriteriaId": "3CBCF6D9-5085-473C-82F5-98BC246A9C4C",
                "versionEndExcluding": "10.0.10240.20947",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x64:*",
                "matchCriteriaId": "0CF0E174-4692-4AA3-B72E-12E73A1BDBE5",
                "versionEndExcluding": "10.0.14393.7876",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x86:*",
                "matchCriteriaId": "340EF5F8-D4F5-4AD8-9D80-1DEC2F376BE5",
                "versionEndExcluding": "10.0.14393.7876",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x64:*",
                "matchCriteriaId": "67C8DCD7-90C4-431F-BD03-FDFDE170E748",
                "versionEndExcluding": "10.0.17763.7009",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x86:*",
                "matchCriteriaId": "05169574-28AB-4E42-B3DE-710574BB1AD3",
                "versionEndExcluding": "10.0.17763.7009",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:arm64:*",
                "matchCriteriaId": "714C0D5E-BE31-45AB-A729-FF55DE59F593",
                "versionEndExcluding": "10.0.19044.5608",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:x64:*",
                "matchCriteriaId": "0C8B2D45-7059-4FA0-A46C-64A171D287DA",
                "versionEndExcluding": "10.0.19044.5608",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:x86:*",
                "matchCriteriaId": "5569800D-B907-47CC-86D2-EC0118157916",
                "versionEndExcluding": "10.0.19044.5608",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:arm64:*",
                "matchCriteriaId": "A84E706C-3A65-4920-8F80-2A684D3CB110",
                "versionEndExcluding": "10.0.19045.5608",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:x64:*",
                "matchCriteriaId": "ED157557-37C1-4802-8746-B87120BA16FA",
                "versionEndExcluding": "10.0.19045.5608",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:x86:*",
                "matchCriteriaId": "BE8F0EF2-EED3-4791-AE26-D24D97B673D6",
                "versionEndExcluding": "10.0.19045.5608",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_11_22h2:*:*:*:*:*:*:arm64:*",
                "matchCriteriaId": "C8949B3E-5847-42F8-A15A-D7515F0EE305",
                "versionEndExcluding": "10.0.22621.5039",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_11_22h2:*:*:*:*:*:*:x64:*",
                "matchCriteriaId": "84D4F97D-3BA2-4B7A-B650-5772DE49CE97",
                "versionEndExcluding": "10.0.22621.5039",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:arm64:*",
                "matchCriteriaId": "82807292-1736-4453-B805-3D471BF94A35",
                "versionEndExcluding": "10.0.22631.5039",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:x64:*",
                "matchCriteriaId": "E19130AD-ECD6-4FC4-B2C8-AB058BDEF928",
                "versionEndExcluding": "10.0.22631.5039",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:arm64:*",
                "matchCriteriaId": "B7ADF37E-1DD3-4539-8922-1E059955FEF1",
                "versionEndExcluding": "10.0.26100.3403",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:x64:*",
                "matchCriteriaId": "E0A74D52-ABC0-4733-B892-F8688B6AEBA7",
                "versionEndExcluding": "10.0.26100.3403",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_server_2008:-:sp2:*:*:*:*:x64:*",
                "matchCriteriaId": "2127D10C-B6F3-4C1D-B9AA-5D78513CC996",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_server_2008:-:sp2:*:*:*:*:x86:*",
                "matchCriteriaId": "AB425562-C0A0-452E-AABE-F70522F15E1A",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:x64:*",
                "matchCriteriaId": "AF07A81D-12E5-4B1D-BFF9-C8D08C32FF4F",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*",
                "matchCriteriaId": "A7DF96F8-BA6A-4780-9CA3-F719B3F81074",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*",
                "matchCriteriaId": "DB18C4CE-5917-401E-ACF7-2747084FD36E",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_server_2016:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "C7610CDB-A02B-4C62-B17F-6DCE2B3DE4F0",
                "versionEndExcluding": "10.0.14393.7876",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_server_2019:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "D271422D-A29F-4DBF-BF72-BCD90E393A5A",
                "versionEndExcluding": "10.0.17763.7009",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_server_2022:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "AAACC9C4-DDC5-4059-AFE3-A49DB2347A86",
                "versionEndExcluding": "10.0.20348.3270",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_server_2022_23h2:*:*:*:*:*:*:x64:*",
                "matchCriteriaId": "96046A7B-76A1-4DCF-AEA5-25344D37E492",
                "versionEndExcluding": "10.0.25398.1486",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:x64:*",
                "matchCriteriaId": "CE542697-31D8-4EC2-8135-F0468431FD19",
                "versionEndExcluding": "10.0.26100.3403",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally."
      },
      {
        "lang": "es",
        "value": "El desbordamiento del búfer basado en montón en Windows NTFS permite que un atacante no autorizado ejecute código localmente."
      }
    ],
    "id": "CVE-2025-24993",
    "lastModified": "2026-09-24T13:10:00.320",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "HIGH",
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 1.8,
          "impactScore": 5.9,
          "source": "secure@microsoft.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-24993",
            "options": [
              {
                "exploitation": "active"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2025-03-14T03:55:33.583406Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2025-03-11T17:16:35.797",
    "references": [
      {
        "source": "secure@microsoft.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-24993"
      },
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "tags": [
          "US Government Resource"
        ],
        "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-24993"
      }
    ],
    "sourceIdentifier": "secure@microsoft.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-122"
          }
        ],
        "source": "secure@microsoft.com",
        "type": "Secondary"
      }
    ]
  }
}
—
Exploited
exploited
CISA Known Exploited Vulnerabilitiesyes
receipt
Source
CISA Known Exploited Vulnerabilities
Its words
yes
Read by
const:yes
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-06 17:36 UTC
What the source handed over
{
  "cveID": "CVE-2025-24993",
  "cwes": "CWE-122",
  "dateAdded": "2025-03-11",
  "dueDate": "2025-04-01",
  "forensicTriage": "No",
  "knownRansomwareCampaignUse": "Unknown",
  "notes": "https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2025-24993 ; https://nvd.nist.gov/vuln/detail/CVE-2025-24993",
  "product": "Windows",
  "requiredAction": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
  "shortDescription": "Microsoft Windows New Technology File System (NTFS) contains a heap-based buffer overflow vulnerability that allows an unauthorized attacker to execute code locally.",
  "vendorProject": "Microsoft",
  "vulnerabilityName": "Microsoft Windows NTFS Heap-Based Buffer Overflow Vulnerability"
}
—
Fixed in
fixed_in
NVD10.0.10240.20947, 10.0.14393.7876, 10.0.17763.7009, 10.0.19044.5608, 10.0.19045.5608, 10.0.22621.5039, 10.0.22631.5039, 10.0.26100.3476, 6.1.7601.27618, 6.0.6003.23168, 6.2.9200.25368, 6.3.9600.22470, 10.0.20348.3328, 10.0.25398.1486
receipt
Source
NVD
Its words
10.0.10240.20947, 10.0.14393.7876, 10.0.17763.7009, 10.0.19044.5608, 10.0.19045.5608, 10.0.22621.5039, 10.0.22631.5039, 10.0.26100.3476, 6.1.7601.27618, 6.0.6003.23168, 6.2.9200.25368, 6.3.9600.22470, 10.0.20348.3328, 10.0.25398.1486
Read by
field:cve.affected[].affectedData[].versions[status=affected].lessThan
Said since
2026-10-06 12:29 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 12:29 UTC10.0.10240.20947, 10.0.14393.7876, 10.0.17763.7009, 10.0.19044.5608, 10.0.19045.5608, 10.0.22621.5039, 10.0.22631.5039, 10.0.26100.3476, 6.1.7601.27618, 6.0.6003.23168, 6.2.9200.25368, 6.3.9600.22470, 10.0.20348.3328, 10.0.25398.1486
2026-10-06 11:54 UTC10.0.10240.20947, 10.0.14393.7876, 10.0.17763.7009, 10.0.19044.5608, 10.0.19045.5608, 10.0.22621.5039, 10.0.22631.5039, 10.0.22631.5039, 10.0.26100.3476, 6.1.7601.27618, 6.1.7601.27618, 6.0.6003.23168, 6.0.6003.23168, 6.2.9200.25368, 6.2.9200.25368, 6.3.9600.22470, 6.3.9600.22470, 10.0.14393.7876, 10.0.14393.7876, 10.0.17763.7009, 10.0.17763.7009, 10.0.20348.3328, 10.0.25398.1486, 10.0.26100.3476, 10.0.26100.3476
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "platforms": [
              "32-bit Systems",
              "x64-based Systems"
            ],
            "product": "Windows 10 Version 1507",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.10240.20947",
                "status": "affected",
                "version": "10.0.10240.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "32-bit Systems",
              "x64-based Systems"
            ],
            "product": "Windows 10 Version 1607",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.14393.7876",
                "status": "affected",
                "version": "10.0.14393.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "32-bit Systems",
              "x64-based Systems"
            ],
            "product": "Windows 10 Version 1809",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.17763.7009",
                "status": "affected",
                "version": "10.0.17763.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "32-bit Systems",
              "ARM64-based Systems",
              "x64-based Systems"
            ],
            "product": "Windows 10 Version 21H2",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.19044.5608",
                "status": "affected",
                "version": "10.0.19044.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "32-bit Systems",
              "ARM64-based Systems",
              "x64-based Systems"
            ],
            "product": "Windows 10 Version 22H2",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.19045.5608",
                "status": "affected",
                "version": "10.0.19045.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "ARM64-based Systems",
              "x64-based Systems"
            ],
            "product": "Windows 11 version 22H2",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.22621.5039",
                "status": "affected",
                "version": "10.0.22621.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "ARM64-based Systems"
            ],
            "product": "Windows 11 version 22H3",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.22631.5039",
                "status": "affected",
                "version": "10.0.22631.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows 11 Version 23H2",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.22631.5039",
                "status": "affected",
                "version": "10.0.22631.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "ARM64-based Systems",
              "x64-based Systems"
            ],
            "product": "Windows 11 Version 24H2",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.26100.3476",
                "status": "affected",
                "version": "10.0.26100.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2008 R2 Service Pack 1",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "6.1.7601.27618",
                "status": "affected",
                "version": "6.1.7601.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2008 R2 Service Pack 1 (Server Core installation)",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "6.1.7601.27618",
                "status": "affected",
                "version": "6.1.7601.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "32-bit Systems",
              "x64-based Systems"
            ],
            "product": "Windows Server 2008 Service Pack 2",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "6.0.6003.23168",
                "status": "affected",
                "version": "6.0.6003.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "32-bit Systems",
              "x64-based Systems"
            ],
            "product": "Windows Server 2008 Service Pack 2 (Server Core installation)",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "6.0.6003.23168",
                "status": "affected",
                "version": "6.0.6003.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2012",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "6.2.9200.25368",
                "status": "affected",
                "version": "6.2.9200.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2012 (Server Core installation)",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "6.2.9200.25368",
                "status": "affected",
                "version": "6.2.9200.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2012 R2",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "6.3.9600.22470",
                "status": "affected",
                "version": "6.3.9600.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2012 R2 (Server Core installation)",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "6.3.9600.22470",
                "status": "affected",
                "version": "6.3.9600.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2016",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.14393.7876",
                "status": "affected",
                "version": "10.0.14393.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2016 (Server Core installation)",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.14393.7876",
                "status": "affected",
                "version": "10.0.14393.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2019",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.17763.7009",
                "status": "affected",
                "version": "10.0.17763.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2019 (Server Core installation)",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.17763.7009",
                "status": "affected",
                "version": "10.0.17763.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2022",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.20348.3328",
                "status": "affected",
                "version": "10.0.20348.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2022, 23H2 Edition (Server Core installation)",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.25398.1486",
                "status": "affected",
                "version": "10.0.25398.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2025",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.26100.3476",
                "status": "affected",
                "version": "10.0.26100.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2025 (Server Core installation)",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.26100.3476",
                "status": "affected",
                "version": "10.0.26100.0",
                "versionType": "custom"
              }
            ]
          }
        ],
        "source": "secure@microsoft.com"
      }
    ],
    "cisaActionDue": "2025-04-01",
    "cisaExploitAdd": "2025-03-11",
    "cisaRequiredAction": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
    "cisaVulnerabilityName": "Microsoft Windows NTFS Heap-Based Buffer Overflow Vulnerability",
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:o:microsoft:windows_10_1507:*:*:*:*:*:*:x64:*",
                "matchCriteriaId": "6997DE6E-CBAD-4690-A68C-8F10E477DCC2",
                "versionEndExcluding": "10.0.10240.20947",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_10_1507:*:*:*:*:*:*:x86:*",
                "matchCriteriaId": "3CBCF6D9-5085-473C-82F5-98BC246A9C4C",
                "versionEndExcluding": "10.0.10240.20947",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x64:*",
                "matchCriteriaId": "0CF0E174-4692-4AA3-B72E-12E73A1BDBE5",
                "versionEndExcluding": "10.0.14393.7876",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x86:*",
                "matchCriteriaId": "340EF5F8-D4F5-4AD8-9D80-1DEC2F376BE5",
                "versionEndExcluding": "10.0.14393.7876",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x64:*",
                "matchCriteriaId": "67C8DCD7-90C4-431F-BD03-FDFDE170E748",
                "versionEndExcluding": "10.0.17763.7009",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x86:*",
                "matchCriteriaId": "05169574-28AB-4E42-B3DE-710574BB1AD3",
                "versionEndExcluding": "10.0.17763.7009",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:arm64:*",
                "matchCriteriaId": "714C0D5E-BE31-45AB-A729-FF55DE59F593",
                "versionEndExcluding": "10.0.19044.5608",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:x64:*",
                "matchCriteriaId": "0C8B2D45-7059-4FA0-A46C-64A171D287DA",
                "versionEndExcluding": "10.0.19044.5608",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:x86:*",
                "matchCriteriaId": "5569800D-B907-47CC-86D2-EC0118157916",
                "versionEndExcluding": "10.0.19044.5608",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:arm64:*",
                "matchCriteriaId": "A84E706C-3A65-4920-8F80-2A684D3CB110",
                "versionEndExcluding": "10.0.19045.5608",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:x64:*",
                "matchCriteriaId": "ED157557-37C1-4802-8746-B87120BA16FA",
                "versionEndExcluding": "10.0.19045.5608",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:x86:*",
                "matchCriteriaId": "BE8F0EF2-EED3-4791-AE26-D24D97B673D6",
                "versionEndExcluding": "10.0.19045.5608",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_11_22h2:*:*:*:*:*:*:arm64:*",
                "matchCriteriaId": "C8949B3E-5847-42F8-A15A-D7515F0EE305",
                "versionEndExcluding": "10.0.22621.5039",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_11_22h2:*:*:*:*:*:*:x64:*",
                "matchCriteriaId": "84D4F97D-3BA2-4B7A-B650-5772DE49CE97",
                "versionEndExcluding": "10.0.22621.5039",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:arm64:*",
                "matchCriteriaId": "82807292-1736-4453-B805-3D471BF94A35",
                "versionEndExcluding": "10.0.22631.5039",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:x64:*",
                "matchCriteriaId": "E19130AD-ECD6-4FC4-B2C8-AB058BDEF928",
                "versionEndExcluding": "10.0.22631.5039",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:arm64:*",
                "matchCriteriaId": "B7ADF37E-1DD3-4539-8922-1E059955FEF1",
                "versionEndExcluding": "10.0.26100.3403",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:x64:*",
                "matchCriteriaId": "E0A74D52-ABC0-4733-B892-F8688B6AEBA7",
                "versionEndExcluding": "10.0.26100.3403",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_server_2008:-:sp2:*:*:*:*:x64:*",
                "matchCriteriaId": "2127D10C-B6F3-4C1D-B9AA-5D78513CC996",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_server_2008:-:sp2:*:*:*:*:x86:*",
                "matchCriteriaId": "AB425562-C0A0-452E-AABE-F70522F15E1A",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:x64:*",
                "matchCriteriaId": "AF07A81D-12E5-4B1D-BFF9-C8D08C32FF4F",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*",
                "matchCriteriaId": "A7DF96F8-BA6A-4780-9CA3-F719B3F81074",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*",
                "matchCriteriaId": "DB18C4CE-5917-401E-ACF7-2747084FD36E",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_server_2016:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "C7610CDB-A02B-4C62-B17F-6DCE2B3DE4F0",
                "versionEndExcluding": "10.0.14393.7876",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_server_2019:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "D271422D-A29F-4DBF-BF72-BCD90E393A5A",
                "versionEndExcluding": "10.0.17763.7009",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_server_2022:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "AAACC9C4-DDC5-4059-AFE3-A49DB2347A86",
                "versionEndExcluding": "10.0.20348.3270",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_server_2022_23h2:*:*:*:*:*:*:x64:*",
                "matchCriteriaId": "96046A7B-76A1-4DCF-AEA5-25344D37E492",
                "versionEndExcluding": "10.0.25398.1486",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:x64:*",
                "matchCriteriaId": "CE542697-31D8-4EC2-8135-F0468431FD19",
                "versionEndExcluding": "10.0.26100.3403",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally."
      },
      {
        "lang": "es",
        "value": "El desbordamiento del búfer basado en montón en Windows NTFS permite que un atacante no autorizado ejecute código localmente."
      }
    ],
    "id": "CVE-2025-24993",
    "lastModified": "2026-09-24T13:10:00.320",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "HIGH",
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 1.8,
          "impactScore": 5.9,
          "source": "secure@microsoft.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-24993",
            "options": [
              {
                "exploitation": "active"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2025-03-14T03:55:33.583406Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2025-03-11T17:16:35.797",
    "references": [
      {
        "source": "secure@microsoft.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-24993"
      },
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "tags": [
          "US Government Resource"
        ],
        "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-24993"
      }
    ],
    "sourceIdentifier": "secure@microsoft.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-122"
          }
        ],
        "source": "secure@microsoft.com",
        "type": "Secondary"
      }
    ]
  }
}
—
Forensic triage
forensic_triage
CISA Known Exploited Vulnerabilitiesfalse
receipt
Source
CISA Known Exploited Vulnerabilities
Its words
No
Read by
field:forensicTriage
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-06 17:36 UTC
What the source handed over
{
  "cveID": "CVE-2025-24993",
  "cwes": "CWE-122",
  "dateAdded": "2025-03-11",
  "dueDate": "2025-04-01",
  "forensicTriage": "No",
  "knownRansomwareCampaignUse": "Unknown",
  "notes": "https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2025-24993 ; https://nvd.nist.gov/vuln/detail/CVE-2025-24993",
  "product": "Windows",
  "requiredAction": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
  "shortDescription": "Microsoft Windows New Technology File System (NTFS) contains a heap-based buffer overflow vulnerability that allows an unauthorized attacker to execute code locally.",
  "vendorProject": "Microsoft",
  "vulnerabilityName": "Microsoft Windows NTFS Heap-Based Buffer Overflow Vulnerability"
}
—
Known ransomware campaign use
known_ransomware_campaign_use
CISA Known Exploited VulnerabilitiesUnknown
receipt
Source
CISA Known Exploited Vulnerabilities
Its words
Unknown
Read by
field:knownRansomwareCampaignUse
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-06 17:36 UTC
What the source handed over
{
  "cveID": "CVE-2025-24993",
  "cwes": "CWE-122",
  "dateAdded": "2025-03-11",
  "dueDate": "2025-04-01",
  "forensicTriage": "No",
  "knownRansomwareCampaignUse": "Unknown",
  "notes": "https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2025-24993 ; https://nvd.nist.gov/vuln/detail/CVE-2025-24993",
  "product": "Windows",
  "requiredAction": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
  "shortDescription": "Microsoft Windows New Technology File System (NTFS) contains a heap-based buffer overflow vulnerability that allows an unauthorized attacker to execute code locally.",
  "vendorProject": "Microsoft",
  "vulnerabilityName": "Microsoft Windows NTFS Heap-Based Buffer Overflow Vulnerability"
}
—
Product
product
different words
CISA Known Exploited VulnerabilitiesWindows
receipt
Source
CISA Known Exploited Vulnerabilities
Its words
Windows
Read by
field:product
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-06 17:36 UTC
What the source handed over
{
  "cveID": "CVE-2025-24993",
  "cwes": "CWE-122",
  "dateAdded": "2025-03-11",
  "dueDate": "2025-04-01",
  "forensicTriage": "No",
  "knownRansomwareCampaignUse": "Unknown",
  "notes": "https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2025-24993 ; https://nvd.nist.gov/vuln/detail/CVE-2025-24993",
  "product": "Windows",
  "requiredAction": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
  "shortDescription": "Microsoft Windows New Technology File System (NTFS) contains a heap-based buffer overflow vulnerability that allows an unauthorized attacker to execute code locally.",
  "vendorProject": "Microsoft",
  "vulnerabilityName": "Microsoft Windows NTFS Heap-Based Buffer Overflow Vulnerability"
}
—
Product
product
different words
NVDWindows 10 Version 1507
receipt
Source
NVD
Its words
Windows 10 Version 1507
Read by
field:cve.affected[].affectedData[].product
Said since
2026-09-29 17:49 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-09-29 17:49 UTCWindows 10 Version 1507
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "platforms": [
              "32-bit Systems",
              "x64-based Systems"
            ],
            "product": "Windows 10 Version 1507",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.10240.20947",
                "status": "affected",
                "version": "10.0.10240.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "32-bit Systems",
              "x64-based Systems"
            ],
            "product": "Windows 10 Version 1607",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.14393.7876",
                "status": "affected",
                "version": "10.0.14393.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "32-bit Systems",
              "x64-based Systems"
            ],
            "product": "Windows 10 Version 1809",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.17763.7009",
                "status": "affected",
                "version": "10.0.17763.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "32-bit Systems",
              "ARM64-based Systems",
              "x64-based Systems"
            ],
            "product": "Windows 10 Version 21H2",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.19044.5608",
                "status": "affected",
                "version": "10.0.19044.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "32-bit Systems",
              "ARM64-based Systems",
              "x64-based Systems"
            ],
            "product": "Windows 10 Version 22H2",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.19045.5608",
                "status": "affected",
                "version": "10.0.19045.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "ARM64-based Systems",
              "x64-based Systems"
            ],
            "product": "Windows 11 version 22H2",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.22621.5039",
                "status": "affected",
                "version": "10.0.22621.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "ARM64-based Systems"
            ],
            "product": "Windows 11 version 22H3",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.22631.5039",
                "status": "affected",
                "version": "10.0.22631.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows 11 Version 23H2",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.22631.5039",
                "status": "affected",
                "version": "10.0.22631.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "ARM64-based Systems",
              "x64-based Systems"
            ],
            "product": "Windows 11 Version 24H2",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.26100.3476",
                "status": "affected",
                "version": "10.0.26100.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2008 R2 Service Pack 1",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "6.1.7601.27618",
                "status": "affected",
                "version": "6.1.7601.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2008 R2 Service Pack 1 (Server Core installation)",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "6.1.7601.27618",
                "status": "affected",
                "version": "6.1.7601.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "32-bit Systems",
              "x64-based Systems"
            ],
            "product": "Windows Server 2008 Service Pack 2",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "6.0.6003.23168",
                "status": "affected",
                "version": "6.0.6003.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "32-bit Systems",
              "x64-based Systems"
            ],
            "product": "Windows Server 2008 Service Pack 2 (Server Core installation)",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "6.0.6003.23168",
                "status": "affected",
                "version": "6.0.6003.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2012",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "6.2.9200.25368",
                "status": "affected",
                "version": "6.2.9200.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2012 (Server Core installation)",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "6.2.9200.25368",
                "status": "affected",
                "version": "6.2.9200.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2012 R2",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "6.3.9600.22470",
                "status": "affected",
                "version": "6.3.9600.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2012 R2 (Server Core installation)",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "6.3.9600.22470",
                "status": "affected",
                "version": "6.3.9600.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2016",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.14393.7876",
                "status": "affected",
                "version": "10.0.14393.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2016 (Server Core installation)",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.14393.7876",
                "status": "affected",
                "version": "10.0.14393.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2019",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.17763.7009",
                "status": "affected",
                "version": "10.0.17763.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2019 (Server Core installation)",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.17763.7009",
                "status": "affected",
                "version": "10.0.17763.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2022",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.20348.3328",
                "status": "affected",
                "version": "10.0.20348.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2022, 23H2 Edition (Server Core installation)",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.25398.1486",
                "status": "affected",
                "version": "10.0.25398.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2025",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.26100.3476",
                "status": "affected",
                "version": "10.0.26100.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2025 (Server Core installation)",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.26100.3476",
                "status": "affected",
                "version": "10.0.26100.0",
                "versionType": "custom"
              }
            ]
          }
        ],
        "source": "secure@microsoft.com"
      }
    ],
    "cisaActionDue": "2025-04-01",
    "cisaExploitAdd": "2025-03-11",
    "cisaRequiredAction": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
    "cisaVulnerabilityName": "Microsoft Windows NTFS Heap-Based Buffer Overflow Vulnerability",
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:o:microsoft:windows_10_1507:*:*:*:*:*:*:x64:*",
                "matchCriteriaId": "6997DE6E-CBAD-4690-A68C-8F10E477DCC2",
                "versionEndExcluding": "10.0.10240.20947",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_10_1507:*:*:*:*:*:*:x86:*",
                "matchCriteriaId": "3CBCF6D9-5085-473C-82F5-98BC246A9C4C",
                "versionEndExcluding": "10.0.10240.20947",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x64:*",
                "matchCriteriaId": "0CF0E174-4692-4AA3-B72E-12E73A1BDBE5",
                "versionEndExcluding": "10.0.14393.7876",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x86:*",
                "matchCriteriaId": "340EF5F8-D4F5-4AD8-9D80-1DEC2F376BE5",
                "versionEndExcluding": "10.0.14393.7876",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x64:*",
                "matchCriteriaId": "67C8DCD7-90C4-431F-BD03-FDFDE170E748",
                "versionEndExcluding": "10.0.17763.7009",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x86:*",
                "matchCriteriaId": "05169574-28AB-4E42-B3DE-710574BB1AD3",
                "versionEndExcluding": "10.0.17763.7009",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:arm64:*",
                "matchCriteriaId": "714C0D5E-BE31-45AB-A729-FF55DE59F593",
                "versionEndExcluding": "10.0.19044.5608",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:x64:*",
                "matchCriteriaId": "0C8B2D45-7059-4FA0-A46C-64A171D287DA",
                "versionEndExcluding": "10.0.19044.5608",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:x86:*",
                "matchCriteriaId": "5569800D-B907-47CC-86D2-EC0118157916",
                "versionEndExcluding": "10.0.19044.5608",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:arm64:*",
                "matchCriteriaId": "A84E706C-3A65-4920-8F80-2A684D3CB110",
                "versionEndExcluding": "10.0.19045.5608",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:x64:*",
                "matchCriteriaId": "ED157557-37C1-4802-8746-B87120BA16FA",
                "versionEndExcluding": "10.0.19045.5608",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:x86:*",
                "matchCriteriaId": "BE8F0EF2-EED3-4791-AE26-D24D97B673D6",
                "versionEndExcluding": "10.0.19045.5608",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_11_22h2:*:*:*:*:*:*:arm64:*",
                "matchCriteriaId": "C8949B3E-5847-42F8-A15A-D7515F0EE305",
                "versionEndExcluding": "10.0.22621.5039",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_11_22h2:*:*:*:*:*:*:x64:*",
                "matchCriteriaId": "84D4F97D-3BA2-4B7A-B650-5772DE49CE97",
                "versionEndExcluding": "10.0.22621.5039",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:arm64:*",
                "matchCriteriaId": "82807292-1736-4453-B805-3D471BF94A35",
                "versionEndExcluding": "10.0.22631.5039",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:x64:*",
                "matchCriteriaId": "E19130AD-ECD6-4FC4-B2C8-AB058BDEF928",
                "versionEndExcluding": "10.0.22631.5039",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:arm64:*",
                "matchCriteriaId": "B7ADF37E-1DD3-4539-8922-1E059955FEF1",
                "versionEndExcluding": "10.0.26100.3403",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:x64:*",
                "matchCriteriaId": "E0A74D52-ABC0-4733-B892-F8688B6AEBA7",
                "versionEndExcluding": "10.0.26100.3403",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_server_2008:-:sp2:*:*:*:*:x64:*",
                "matchCriteriaId": "2127D10C-B6F3-4C1D-B9AA-5D78513CC996",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_server_2008:-:sp2:*:*:*:*:x86:*",
                "matchCriteriaId": "AB425562-C0A0-452E-AABE-F70522F15E1A",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:x64:*",
                "matchCriteriaId": "AF07A81D-12E5-4B1D-BFF9-C8D08C32FF4F",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*",
                "matchCriteriaId": "A7DF96F8-BA6A-4780-9CA3-F719B3F81074",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*",
                "matchCriteriaId": "DB18C4CE-5917-401E-ACF7-2747084FD36E",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_server_2016:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "C7610CDB-A02B-4C62-B17F-6DCE2B3DE4F0",
                "versionEndExcluding": "10.0.14393.7876",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_server_2019:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "D271422D-A29F-4DBF-BF72-BCD90E393A5A",
                "versionEndExcluding": "10.0.17763.7009",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_server_2022:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "AAACC9C4-DDC5-4059-AFE3-A49DB2347A86",
                "versionEndExcluding": "10.0.20348.3270",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_server_2022_23h2:*:*:*:*:*:*:x64:*",
                "matchCriteriaId": "96046A7B-76A1-4DCF-AEA5-25344D37E492",
                "versionEndExcluding": "10.0.25398.1486",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:x64:*",
                "matchCriteriaId": "CE542697-31D8-4EC2-8135-F0468431FD19",
                "versionEndExcluding": "10.0.26100.3403",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally."
      },
      {
        "lang": "es",
        "value": "El desbordamiento del búfer basado en montón en Windows NTFS permite que un atacante no autorizado ejecute código localmente."
      }
    ],
    "id": "CVE-2025-24993",
    "lastModified": "2026-09-24T13:10:00.320",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "HIGH",
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 1.8,
          "impactScore": 5.9,
          "source": "secure@microsoft.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-24993",
            "options": [
              {
                "exploitation": "active"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2025-03-14T03:55:33.583406Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2025-03-11T17:16:35.797",
    "references": [
      {
        "source": "secure@microsoft.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-24993"
      },
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "tags": [
          "US Government Resource"
        ],
        "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-24993"
      }
    ],
    "sourceIdentifier": "secure@microsoft.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-122"
          }
        ],
        "source": "secure@microsoft.com",
        "type": "Secondary"
      }
    ]
  }
}
—
Severity
severity
NVDHIGH
From 7.0 to 8.9.
receipt
Source
NVD
Its words
HIGH
Read by
field:cve.metrics.cvssMetricV31[type=Primary].cvssData.baseSeverity || field:cve.metrics.cvssMetricV31[].cvssData.baseSeverity
Said since
2026-10-06 11:54 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 11:54 UTCHIGH
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "platforms": [
              "32-bit Systems",
              "x64-based Systems"
            ],
            "product": "Windows 10 Version 1507",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.10240.20947",
                "status": "affected",
                "version": "10.0.10240.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "32-bit Systems",
              "x64-based Systems"
            ],
            "product": "Windows 10 Version 1607",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.14393.7876",
                "status": "affected",
                "version": "10.0.14393.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "32-bit Systems",
              "x64-based Systems"
            ],
            "product": "Windows 10 Version 1809",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.17763.7009",
                "status": "affected",
                "version": "10.0.17763.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "32-bit Systems",
              "ARM64-based Systems",
              "x64-based Systems"
            ],
            "product": "Windows 10 Version 21H2",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.19044.5608",
                "status": "affected",
                "version": "10.0.19044.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "32-bit Systems",
              "ARM64-based Systems",
              "x64-based Systems"
            ],
            "product": "Windows 10 Version 22H2",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.19045.5608",
                "status": "affected",
                "version": "10.0.19045.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "ARM64-based Systems",
              "x64-based Systems"
            ],
            "product": "Windows 11 version 22H2",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.22621.5039",
                "status": "affected",
                "version": "10.0.22621.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "ARM64-based Systems"
            ],
            "product": "Windows 11 version 22H3",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.22631.5039",
                "status": "affected",
                "version": "10.0.22631.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows 11 Version 23H2",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.22631.5039",
                "status": "affected",
                "version": "10.0.22631.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "ARM64-based Systems",
              "x64-based Systems"
            ],
            "product": "Windows 11 Version 24H2",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.26100.3476",
                "status": "affected",
                "version": "10.0.26100.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2008 R2 Service Pack 1",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "6.1.7601.27618",
                "status": "affected",
                "version": "6.1.7601.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2008 R2 Service Pack 1 (Server Core installation)",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "6.1.7601.27618",
                "status": "affected",
                "version": "6.1.7601.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "32-bit Systems",
              "x64-based Systems"
            ],
            "product": "Windows Server 2008 Service Pack 2",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "6.0.6003.23168",
                "status": "affected",
                "version": "6.0.6003.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "32-bit Systems",
              "x64-based Systems"
            ],
            "product": "Windows Server 2008 Service Pack 2 (Server Core installation)",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "6.0.6003.23168",
                "status": "affected",
                "version": "6.0.6003.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2012",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "6.2.9200.25368",
                "status": "affected",
                "version": "6.2.9200.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2012 (Server Core installation)",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "6.2.9200.25368",
                "status": "affected",
                "version": "6.2.9200.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2012 R2",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "6.3.9600.22470",
                "status": "affected",
                "version": "6.3.9600.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2012 R2 (Server Core installation)",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "6.3.9600.22470",
                "status": "affected",
                "version": "6.3.9600.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2016",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.14393.7876",
                "status": "affected",
                "version": "10.0.14393.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2016 (Server Core installation)",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.14393.7876",
                "status": "affected",
                "version": "10.0.14393.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2019",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.17763.7009",
                "status": "affected",
                "version": "10.0.17763.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2019 (Server Core installation)",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.17763.7009",
                "status": "affected",
                "version": "10.0.17763.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2022",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.20348.3328",
                "status": "affected",
                "version": "10.0.20348.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2022, 23H2 Edition (Server Core installation)",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.25398.1486",
                "status": "affected",
                "version": "10.0.25398.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2025",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.26100.3476",
                "status": "affected",
                "version": "10.0.26100.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2025 (Server Core installation)",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.26100.3476",
                "status": "affected",
                "version": "10.0.26100.0",
                "versionType": "custom"
              }
            ]
          }
        ],
        "source": "secure@microsoft.com"
      }
    ],
    "cisaActionDue": "2025-04-01",
    "cisaExploitAdd": "2025-03-11",
    "cisaRequiredAction": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
    "cisaVulnerabilityName": "Microsoft Windows NTFS Heap-Based Buffer Overflow Vulnerability",
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:o:microsoft:windows_10_1507:*:*:*:*:*:*:x64:*",
                "matchCriteriaId": "6997DE6E-CBAD-4690-A68C-8F10E477DCC2",
                "versionEndExcluding": "10.0.10240.20947",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_10_1507:*:*:*:*:*:*:x86:*",
                "matchCriteriaId": "3CBCF6D9-5085-473C-82F5-98BC246A9C4C",
                "versionEndExcluding": "10.0.10240.20947",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x64:*",
                "matchCriteriaId": "0CF0E174-4692-4AA3-B72E-12E73A1BDBE5",
                "versionEndExcluding": "10.0.14393.7876",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x86:*",
                "matchCriteriaId": "340EF5F8-D4F5-4AD8-9D80-1DEC2F376BE5",
                "versionEndExcluding": "10.0.14393.7876",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x64:*",
                "matchCriteriaId": "67C8DCD7-90C4-431F-BD03-FDFDE170E748",
                "versionEndExcluding": "10.0.17763.7009",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x86:*",
                "matchCriteriaId": "05169574-28AB-4E42-B3DE-710574BB1AD3",
                "versionEndExcluding": "10.0.17763.7009",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:arm64:*",
                "matchCriteriaId": "714C0D5E-BE31-45AB-A729-FF55DE59F593",
                "versionEndExcluding": "10.0.19044.5608",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:x64:*",
                "matchCriteriaId": "0C8B2D45-7059-4FA0-A46C-64A171D287DA",
                "versionEndExcluding": "10.0.19044.5608",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:x86:*",
                "matchCriteriaId": "5569800D-B907-47CC-86D2-EC0118157916",
                "versionEndExcluding": "10.0.19044.5608",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:arm64:*",
                "matchCriteriaId": "A84E706C-3A65-4920-8F80-2A684D3CB110",
                "versionEndExcluding": "10.0.19045.5608",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:x64:*",
                "matchCriteriaId": "ED157557-37C1-4802-8746-B87120BA16FA",
                "versionEndExcluding": "10.0.19045.5608",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:x86:*",
                "matchCriteriaId": "BE8F0EF2-EED3-4791-AE26-D24D97B673D6",
                "versionEndExcluding": "10.0.19045.5608",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_11_22h2:*:*:*:*:*:*:arm64:*",
                "matchCriteriaId": "C8949B3E-5847-42F8-A15A-D7515F0EE305",
                "versionEndExcluding": "10.0.22621.5039",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_11_22h2:*:*:*:*:*:*:x64:*",
                "matchCriteriaId": "84D4F97D-3BA2-4B7A-B650-5772DE49CE97",
                "versionEndExcluding": "10.0.22621.5039",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:arm64:*",
                "matchCriteriaId": "82807292-1736-4453-B805-3D471BF94A35",
                "versionEndExcluding": "10.0.22631.5039",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:x64:*",
                "matchCriteriaId": "E19130AD-ECD6-4FC4-B2C8-AB058BDEF928",
                "versionEndExcluding": "10.0.22631.5039",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:arm64:*",
                "matchCriteriaId": "B7ADF37E-1DD3-4539-8922-1E059955FEF1",
                "versionEndExcluding": "10.0.26100.3403",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:x64:*",
                "matchCriteriaId": "E0A74D52-ABC0-4733-B892-F8688B6AEBA7",
                "versionEndExcluding": "10.0.26100.3403",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_server_2008:-:sp2:*:*:*:*:x64:*",
                "matchCriteriaId": "2127D10C-B6F3-4C1D-B9AA-5D78513CC996",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_server_2008:-:sp2:*:*:*:*:x86:*",
                "matchCriteriaId": "AB425562-C0A0-452E-AABE-F70522F15E1A",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:x64:*",
                "matchCriteriaId": "AF07A81D-12E5-4B1D-BFF9-C8D08C32FF4F",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*",
                "matchCriteriaId": "A7DF96F8-BA6A-4780-9CA3-F719B3F81074",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*",
                "matchCriteriaId": "DB18C4CE-5917-401E-ACF7-2747084FD36E",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_server_2016:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "C7610CDB-A02B-4C62-B17F-6DCE2B3DE4F0",
                "versionEndExcluding": "10.0.14393.7876",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_server_2019:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "D271422D-A29F-4DBF-BF72-BCD90E393A5A",
                "versionEndExcluding": "10.0.17763.7009",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_server_2022:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "AAACC9C4-DDC5-4059-AFE3-A49DB2347A86",
                "versionEndExcluding": "10.0.20348.3270",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_server_2022_23h2:*:*:*:*:*:*:x64:*",
                "matchCriteriaId": "96046A7B-76A1-4DCF-AEA5-25344D37E492",
                "versionEndExcluding": "10.0.25398.1486",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:x64:*",
                "matchCriteriaId": "CE542697-31D8-4EC2-8135-F0468431FD19",
                "versionEndExcluding": "10.0.26100.3403",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally."
      },
      {
        "lang": "es",
        "value": "El desbordamiento del búfer basado en montón en Windows NTFS permite que un atacante no autorizado ejecute código localmente."
      }
    ],
    "id": "CVE-2025-24993",
    "lastModified": "2026-09-24T13:10:00.320",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "HIGH",
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 1.8,
          "impactScore": 5.9,
          "source": "secure@microsoft.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-24993",
            "options": [
              {
                "exploitation": "active"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2025-03-14T03:55:33.583406Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2025-03-11T17:16:35.797",
    "references": [
      {
        "source": "secure@microsoft.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-24993"
      },
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "tags": [
          "US Government Resource"
        ],
        "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-24993"
      }
    ],
    "sourceIdentifier": "secure@microsoft.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-122"
          }
        ],
        "source": "secure@microsoft.com",
        "type": "Secondary"
      }
    ]
  }
}
high
Status
status
NVDAnalyzed
receipt
Source
NVD
Its words
Analyzed
Read by
field:cve.vulnStatus
Said since
2026-09-29 09:45 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "platforms": [
              "32-bit Systems",
              "x64-based Systems"
            ],
            "product": "Windows 10 Version 1507",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.10240.20947",
                "status": "affected",
                "version": "10.0.10240.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "32-bit Systems",
              "x64-based Systems"
            ],
            "product": "Windows 10 Version 1607",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.14393.7876",
                "status": "affected",
                "version": "10.0.14393.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "32-bit Systems",
              "x64-based Systems"
            ],
            "product": "Windows 10 Version 1809",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.17763.7009",
                "status": "affected",
                "version": "10.0.17763.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "32-bit Systems",
              "ARM64-based Systems",
              "x64-based Systems"
            ],
            "product": "Windows 10 Version 21H2",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.19044.5608",
                "status": "affected",
                "version": "10.0.19044.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "32-bit Systems",
              "ARM64-based Systems",
              "x64-based Systems"
            ],
            "product": "Windows 10 Version 22H2",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.19045.5608",
                "status": "affected",
                "version": "10.0.19045.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "ARM64-based Systems",
              "x64-based Systems"
            ],
            "product": "Windows 11 version 22H2",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.22621.5039",
                "status": "affected",
                "version": "10.0.22621.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "ARM64-based Systems"
            ],
            "product": "Windows 11 version 22H3",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.22631.5039",
                "status": "affected",
                "version": "10.0.22631.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows 11 Version 23H2",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.22631.5039",
                "status": "affected",
                "version": "10.0.22631.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "ARM64-based Systems",
              "x64-based Systems"
            ],
            "product": "Windows 11 Version 24H2",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.26100.3476",
                "status": "affected",
                "version": "10.0.26100.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2008 R2 Service Pack 1",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "6.1.7601.27618",
                "status": "affected",
                "version": "6.1.7601.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2008 R2 Service Pack 1 (Server Core installation)",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "6.1.7601.27618",
                "status": "affected",
                "version": "6.1.7601.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "32-bit Systems",
              "x64-based Systems"
            ],
            "product": "Windows Server 2008 Service Pack 2",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "6.0.6003.23168",
                "status": "affected",
                "version": "6.0.6003.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "32-bit Systems",
              "x64-based Systems"
            ],
            "product": "Windows Server 2008 Service Pack 2 (Server Core installation)",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "6.0.6003.23168",
                "status": "affected",
                "version": "6.0.6003.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2012",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "6.2.9200.25368",
                "status": "affected",
                "version": "6.2.9200.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2012 (Server Core installation)",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "6.2.9200.25368",
                "status": "affected",
                "version": "6.2.9200.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2012 R2",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "6.3.9600.22470",
                "status": "affected",
                "version": "6.3.9600.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2012 R2 (Server Core installation)",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "6.3.9600.22470",
                "status": "affected",
                "version": "6.3.9600.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2016",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.14393.7876",
                "status": "affected",
                "version": "10.0.14393.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2016 (Server Core installation)",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.14393.7876",
                "status": "affected",
                "version": "10.0.14393.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2019",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.17763.7009",
                "status": "affected",
                "version": "10.0.17763.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2019 (Server Core installation)",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.17763.7009",
                "status": "affected",
                "version": "10.0.17763.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2022",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.20348.3328",
                "status": "affected",
                "version": "10.0.20348.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2022, 23H2 Edition (Server Core installation)",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.25398.1486",
                "status": "affected",
                "version": "10.0.25398.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2025",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.26100.3476",
                "status": "affected",
                "version": "10.0.26100.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2025 (Server Core installation)",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.26100.3476",
                "status": "affected",
                "version": "10.0.26100.0",
                "versionType": "custom"
              }
            ]
          }
        ],
        "source": "secure@microsoft.com"
      }
    ],
    "cisaActionDue": "2025-04-01",
    "cisaExploitAdd": "2025-03-11",
    "cisaRequiredAction": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
    "cisaVulnerabilityName": "Microsoft Windows NTFS Heap-Based Buffer Overflow Vulnerability",
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:o:microsoft:windows_10_1507:*:*:*:*:*:*:x64:*",
                "matchCriteriaId": "6997DE6E-CBAD-4690-A68C-8F10E477DCC2",
                "versionEndExcluding": "10.0.10240.20947",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_10_1507:*:*:*:*:*:*:x86:*",
                "matchCriteriaId": "3CBCF6D9-5085-473C-82F5-98BC246A9C4C",
                "versionEndExcluding": "10.0.10240.20947",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x64:*",
                "matchCriteriaId": "0CF0E174-4692-4AA3-B72E-12E73A1BDBE5",
                "versionEndExcluding": "10.0.14393.7876",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x86:*",
                "matchCriteriaId": "340EF5F8-D4F5-4AD8-9D80-1DEC2F376BE5",
                "versionEndExcluding": "10.0.14393.7876",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x64:*",
                "matchCriteriaId": "67C8DCD7-90C4-431F-BD03-FDFDE170E748",
                "versionEndExcluding": "10.0.17763.7009",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x86:*",
                "matchCriteriaId": "05169574-28AB-4E42-B3DE-710574BB1AD3",
                "versionEndExcluding": "10.0.17763.7009",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:arm64:*",
                "matchCriteriaId": "714C0D5E-BE31-45AB-A729-FF55DE59F593",
                "versionEndExcluding": "10.0.19044.5608",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:x64:*",
                "matchCriteriaId": "0C8B2D45-7059-4FA0-A46C-64A171D287DA",
                "versionEndExcluding": "10.0.19044.5608",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:x86:*",
                "matchCriteriaId": "5569800D-B907-47CC-86D2-EC0118157916",
                "versionEndExcluding": "10.0.19044.5608",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:arm64:*",
                "matchCriteriaId": "A84E706C-3A65-4920-8F80-2A684D3CB110",
                "versionEndExcluding": "10.0.19045.5608",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:x64:*",
                "matchCriteriaId": "ED157557-37C1-4802-8746-B87120BA16FA",
                "versionEndExcluding": "10.0.19045.5608",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:x86:*",
                "matchCriteriaId": "BE8F0EF2-EED3-4791-AE26-D24D97B673D6",
                "versionEndExcluding": "10.0.19045.5608",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_11_22h2:*:*:*:*:*:*:arm64:*",
                "matchCriteriaId": "C8949B3E-5847-42F8-A15A-D7515F0EE305",
                "versionEndExcluding": "10.0.22621.5039",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_11_22h2:*:*:*:*:*:*:x64:*",
                "matchCriteriaId": "84D4F97D-3BA2-4B7A-B650-5772DE49CE97",
                "versionEndExcluding": "10.0.22621.5039",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:arm64:*",
                "matchCriteriaId": "82807292-1736-4453-B805-3D471BF94A35",
                "versionEndExcluding": "10.0.22631.5039",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:x64:*",
                "matchCriteriaId": "E19130AD-ECD6-4FC4-B2C8-AB058BDEF928",
                "versionEndExcluding": "10.0.22631.5039",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:arm64:*",
                "matchCriteriaId": "B7ADF37E-1DD3-4539-8922-1E059955FEF1",
                "versionEndExcluding": "10.0.26100.3403",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:x64:*",
                "matchCriteriaId": "E0A74D52-ABC0-4733-B892-F8688B6AEBA7",
                "versionEndExcluding": "10.0.26100.3403",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_server_2008:-:sp2:*:*:*:*:x64:*",
                "matchCriteriaId": "2127D10C-B6F3-4C1D-B9AA-5D78513CC996",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_server_2008:-:sp2:*:*:*:*:x86:*",
                "matchCriteriaId": "AB425562-C0A0-452E-AABE-F70522F15E1A",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:x64:*",
                "matchCriteriaId": "AF07A81D-12E5-4B1D-BFF9-C8D08C32FF4F",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*",
                "matchCriteriaId": "A7DF96F8-BA6A-4780-9CA3-F719B3F81074",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*",
                "matchCriteriaId": "DB18C4CE-5917-401E-ACF7-2747084FD36E",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_server_2016:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "C7610CDB-A02B-4C62-B17F-6DCE2B3DE4F0",
                "versionEndExcluding": "10.0.14393.7876",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_server_2019:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "D271422D-A29F-4DBF-BF72-BCD90E393A5A",
                "versionEndExcluding": "10.0.17763.7009",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_server_2022:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "AAACC9C4-DDC5-4059-AFE3-A49DB2347A86",
                "versionEndExcluding": "10.0.20348.3270",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_server_2022_23h2:*:*:*:*:*:*:x64:*",
                "matchCriteriaId": "96046A7B-76A1-4DCF-AEA5-25344D37E492",
                "versionEndExcluding": "10.0.25398.1486",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:x64:*",
                "matchCriteriaId": "CE542697-31D8-4EC2-8135-F0468431FD19",
                "versionEndExcluding": "10.0.26100.3403",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally."
      },
      {
        "lang": "es",
        "value": "El desbordamiento del búfer basado en montón en Windows NTFS permite que un atacante no autorizado ejecute código localmente."
      }
    ],
    "id": "CVE-2025-24993",
    "lastModified": "2026-09-24T13:10:00.320",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "HIGH",
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 1.8,
          "impactScore": 5.9,
          "source": "secure@microsoft.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-24993",
            "options": [
              {
                "exploitation": "active"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2025-03-14T03:55:33.583406Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2025-03-11T17:16:35.797",
    "references": [
      {
        "source": "secure@microsoft.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-24993"
      },
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "tags": [
          "US Government Resource"
        ],
        "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-24993"
      }
    ],
    "sourceIdentifier": "secure@microsoft.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-122"
          }
        ],
        "source": "secure@microsoft.com",
        "type": "Secondary"
      }
    ]
  }
}
—
Technical impact
technical_impact
NVDtotal
The attacker gains full control of the component, or all of its information.
receipt
Source
NVD
Its words
total
Read by
field:cve.metrics.ssvcV203[].ssvcData.options[].technicalImpact
Said since
2026-10-06 11:54 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 11:54 UTCtotal
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "platforms": [
              "32-bit Systems",
              "x64-based Systems"
            ],
            "product": "Windows 10 Version 1507",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.10240.20947",
                "status": "affected",
                "version": "10.0.10240.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "32-bit Systems",
              "x64-based Systems"
            ],
            "product": "Windows 10 Version 1607",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.14393.7876",
                "status": "affected",
                "version": "10.0.14393.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "32-bit Systems",
              "x64-based Systems"
            ],
            "product": "Windows 10 Version 1809",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.17763.7009",
                "status": "affected",
                "version": "10.0.17763.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "32-bit Systems",
              "ARM64-based Systems",
              "x64-based Systems"
            ],
            "product": "Windows 10 Version 21H2",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.19044.5608",
                "status": "affected",
                "version": "10.0.19044.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "32-bit Systems",
              "ARM64-based Systems",
              "x64-based Systems"
            ],
            "product": "Windows 10 Version 22H2",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.19045.5608",
                "status": "affected",
                "version": "10.0.19045.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "ARM64-based Systems",
              "x64-based Systems"
            ],
            "product": "Windows 11 version 22H2",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.22621.5039",
                "status": "affected",
                "version": "10.0.22621.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "ARM64-based Systems"
            ],
            "product": "Windows 11 version 22H3",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.22631.5039",
                "status": "affected",
                "version": "10.0.22631.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows 11 Version 23H2",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.22631.5039",
                "status": "affected",
                "version": "10.0.22631.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "ARM64-based Systems",
              "x64-based Systems"
            ],
            "product": "Windows 11 Version 24H2",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.26100.3476",
                "status": "affected",
                "version": "10.0.26100.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2008 R2 Service Pack 1",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "6.1.7601.27618",
                "status": "affected",
                "version": "6.1.7601.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2008 R2 Service Pack 1 (Server Core installation)",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "6.1.7601.27618",
                "status": "affected",
                "version": "6.1.7601.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "32-bit Systems",
              "x64-based Systems"
            ],
            "product": "Windows Server 2008 Service Pack 2",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "6.0.6003.23168",
                "status": "affected",
                "version": "6.0.6003.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "32-bit Systems",
              "x64-based Systems"
            ],
            "product": "Windows Server 2008 Service Pack 2 (Server Core installation)",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "6.0.6003.23168",
                "status": "affected",
                "version": "6.0.6003.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2012",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "6.2.9200.25368",
                "status": "affected",
                "version": "6.2.9200.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2012 (Server Core installation)",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "6.2.9200.25368",
                "status": "affected",
                "version": "6.2.9200.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2012 R2",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "6.3.9600.22470",
                "status": "affected",
                "version": "6.3.9600.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2012 R2 (Server Core installation)",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "6.3.9600.22470",
                "status": "affected",
                "version": "6.3.9600.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2016",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.14393.7876",
                "status": "affected",
                "version": "10.0.14393.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2016 (Server Core installation)",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.14393.7876",
                "status": "affected",
                "version": "10.0.14393.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2019",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.17763.7009",
                "status": "affected",
                "version": "10.0.17763.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2019 (Server Core installation)",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.17763.7009",
                "status": "affected",
                "version": "10.0.17763.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2022",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.20348.3328",
                "status": "affected",
                "version": "10.0.20348.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2022, 23H2 Edition (Server Core installation)",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.25398.1486",
                "status": "affected",
                "version": "10.0.25398.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2025",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.26100.3476",
                "status": "affected",
                "version": "10.0.26100.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2025 (Server Core installation)",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.26100.3476",
                "status": "affected",
                "version": "10.0.26100.0",
                "versionType": "custom"
              }
            ]
          }
        ],
        "source": "secure@microsoft.com"
      }
    ],
    "cisaActionDue": "2025-04-01",
    "cisaExploitAdd": "2025-03-11",
    "cisaRequiredAction": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
    "cisaVulnerabilityName": "Microsoft Windows NTFS Heap-Based Buffer Overflow Vulnerability",
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:o:microsoft:windows_10_1507:*:*:*:*:*:*:x64:*",
                "matchCriteriaId": "6997DE6E-CBAD-4690-A68C-8F10E477DCC2",
                "versionEndExcluding": "10.0.10240.20947",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_10_1507:*:*:*:*:*:*:x86:*",
                "matchCriteriaId": "3CBCF6D9-5085-473C-82F5-98BC246A9C4C",
                "versionEndExcluding": "10.0.10240.20947",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x64:*",
                "matchCriteriaId": "0CF0E174-4692-4AA3-B72E-12E73A1BDBE5",
                "versionEndExcluding": "10.0.14393.7876",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x86:*",
                "matchCriteriaId": "340EF5F8-D4F5-4AD8-9D80-1DEC2F376BE5",
                "versionEndExcluding": "10.0.14393.7876",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x64:*",
                "matchCriteriaId": "67C8DCD7-90C4-431F-BD03-FDFDE170E748",
                "versionEndExcluding": "10.0.17763.7009",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x86:*",
                "matchCriteriaId": "05169574-28AB-4E42-B3DE-710574BB1AD3",
                "versionEndExcluding": "10.0.17763.7009",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:arm64:*",
                "matchCriteriaId": "714C0D5E-BE31-45AB-A729-FF55DE59F593",
                "versionEndExcluding": "10.0.19044.5608",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:x64:*",
                "matchCriteriaId": "0C8B2D45-7059-4FA0-A46C-64A171D287DA",
                "versionEndExcluding": "10.0.19044.5608",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:x86:*",
                "matchCriteriaId": "5569800D-B907-47CC-86D2-EC0118157916",
                "versionEndExcluding": "10.0.19044.5608",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:arm64:*",
                "matchCriteriaId": "A84E706C-3A65-4920-8F80-2A684D3CB110",
                "versionEndExcluding": "10.0.19045.5608",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:x64:*",
                "matchCriteriaId": "ED157557-37C1-4802-8746-B87120BA16FA",
                "versionEndExcluding": "10.0.19045.5608",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:x86:*",
                "matchCriteriaId": "BE8F0EF2-EED3-4791-AE26-D24D97B673D6",
                "versionEndExcluding": "10.0.19045.5608",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_11_22h2:*:*:*:*:*:*:arm64:*",
                "matchCriteriaId": "C8949B3E-5847-42F8-A15A-D7515F0EE305",
                "versionEndExcluding": "10.0.22621.5039",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_11_22h2:*:*:*:*:*:*:x64:*",
                "matchCriteriaId": "84D4F97D-3BA2-4B7A-B650-5772DE49CE97",
                "versionEndExcluding": "10.0.22621.5039",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:arm64:*",
                "matchCriteriaId": "82807292-1736-4453-B805-3D471BF94A35",
                "versionEndExcluding": "10.0.22631.5039",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:x64:*",
                "matchCriteriaId": "E19130AD-ECD6-4FC4-B2C8-AB058BDEF928",
                "versionEndExcluding": "10.0.22631.5039",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:arm64:*",
                "matchCriteriaId": "B7ADF37E-1DD3-4539-8922-1E059955FEF1",
                "versionEndExcluding": "10.0.26100.3403",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:x64:*",
                "matchCriteriaId": "E0A74D52-ABC0-4733-B892-F8688B6AEBA7",
                "versionEndExcluding": "10.0.26100.3403",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_server_2008:-:sp2:*:*:*:*:x64:*",
                "matchCriteriaId": "2127D10C-B6F3-4C1D-B9AA-5D78513CC996",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_server_2008:-:sp2:*:*:*:*:x86:*",
                "matchCriteriaId": "AB425562-C0A0-452E-AABE-F70522F15E1A",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:x64:*",
                "matchCriteriaId": "AF07A81D-12E5-4B1D-BFF9-C8D08C32FF4F",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*",
                "matchCriteriaId": "A7DF96F8-BA6A-4780-9CA3-F719B3F81074",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*",
                "matchCriteriaId": "DB18C4CE-5917-401E-ACF7-2747084FD36E",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_server_2016:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "C7610CDB-A02B-4C62-B17F-6DCE2B3DE4F0",
                "versionEndExcluding": "10.0.14393.7876",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_server_2019:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "D271422D-A29F-4DBF-BF72-BCD90E393A5A",
                "versionEndExcluding": "10.0.17763.7009",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_server_2022:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "AAACC9C4-DDC5-4059-AFE3-A49DB2347A86",
                "versionEndExcluding": "10.0.20348.3270",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_server_2022_23h2:*:*:*:*:*:*:x64:*",
                "matchCriteriaId": "96046A7B-76A1-4DCF-AEA5-25344D37E492",
                "versionEndExcluding": "10.0.25398.1486",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:x64:*",
                "matchCriteriaId": "CE542697-31D8-4EC2-8135-F0468431FD19",
                "versionEndExcluding": "10.0.26100.3403",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally."
      },
      {
        "lang": "es",
        "value": "El desbordamiento del búfer basado en montón en Windows NTFS permite que un atacante no autorizado ejecute código localmente."
      }
    ],
    "id": "CVE-2025-24993",
    "lastModified": "2026-09-24T13:10:00.320",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "HIGH",
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 1.8,
          "impactScore": 5.9,
          "source": "secure@microsoft.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-24993",
            "options": [
              {
                "exploitation": "active"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2025-03-14T03:55:33.583406Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2025-03-11T17:16:35.797",
    "references": [
      {
        "source": "secure@microsoft.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-24993"
      },
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "tags": [
          "US Government Resource"
        ],
        "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-24993"
      }
    ],
    "sourceIdentifier": "secure@microsoft.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-122"
          }
        ],
        "source": "secure@microsoft.com",
        "type": "Secondary"
      }
    ]
  }
}
—
Vendor
vendor
CISA Known Exploited VulnerabilitiesMicrosoft
receipt
Source
CISA Known Exploited Vulnerabilities
Last answered
2026-10-06 17:36 UTC
What the source handed over
{
  "cveID": "CVE-2025-24993",
  "cwes": "CWE-122",
  "dateAdded": "2025-03-11",
  "dueDate": "2025-04-01",
  "forensicTriage": "No",
  "knownRansomwareCampaignUse": "Unknown",
  "notes": "https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2025-24993 ; https://nvd.nist.gov/vuln/detail/CVE-2025-24993",
  "product": "Windows",
  "requiredAction": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
  "shortDescription": "Microsoft Windows New Technology File System (NTFS) contains a heap-based buffer overflow vulnerability that allows an unauthorized attacker to execute code locally.",
  "vendorProject": "Microsoft",
  "vulnerabilityName": "Microsoft Windows NTFS Heap-Based Buffer Overflow Vulnerability"
}
—
Vendor
vendor
NVDMicrosoft
receipt
Source
NVD
Its words
Microsoft
Read by
field:cve.affected[].affectedData[].vendor
Said since
2026-09-29 17:49 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-09-29 17:49 UTCMicrosoft
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "platforms": [
              "32-bit Systems",
              "x64-based Systems"
            ],
            "product": "Windows 10 Version 1507",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.10240.20947",
                "status": "affected",
                "version": "10.0.10240.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "32-bit Systems",
              "x64-based Systems"
            ],
            "product": "Windows 10 Version 1607",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.14393.7876",
                "status": "affected",
                "version": "10.0.14393.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "32-bit Systems",
              "x64-based Systems"
            ],
            "product": "Windows 10 Version 1809",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.17763.7009",
                "status": "affected",
                "version": "10.0.17763.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "32-bit Systems",
              "ARM64-based Systems",
              "x64-based Systems"
            ],
            "product": "Windows 10 Version 21H2",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.19044.5608",
                "status": "affected",
                "version": "10.0.19044.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "32-bit Systems",
              "ARM64-based Systems",
              "x64-based Systems"
            ],
            "product": "Windows 10 Version 22H2",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.19045.5608",
                "status": "affected",
                "version": "10.0.19045.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "ARM64-based Systems",
              "x64-based Systems"
            ],
            "product": "Windows 11 version 22H2",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.22621.5039",
                "status": "affected",
                "version": "10.0.22621.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "ARM64-based Systems"
            ],
            "product": "Windows 11 version 22H3",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.22631.5039",
                "status": "affected",
                "version": "10.0.22631.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows 11 Version 23H2",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.22631.5039",
                "status": "affected",
                "version": "10.0.22631.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "ARM64-based Systems",
              "x64-based Systems"
            ],
            "product": "Windows 11 Version 24H2",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.26100.3476",
                "status": "affected",
                "version": "10.0.26100.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2008 R2 Service Pack 1",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "6.1.7601.27618",
                "status": "affected",
                "version": "6.1.7601.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2008 R2 Service Pack 1 (Server Core installation)",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "6.1.7601.27618",
                "status": "affected",
                "version": "6.1.7601.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "32-bit Systems",
              "x64-based Systems"
            ],
            "product": "Windows Server 2008 Service Pack 2",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "6.0.6003.23168",
                "status": "affected",
                "version": "6.0.6003.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "32-bit Systems",
              "x64-based Systems"
            ],
            "product": "Windows Server 2008 Service Pack 2 (Server Core installation)",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "6.0.6003.23168",
                "status": "affected",
                "version": "6.0.6003.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2012",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "6.2.9200.25368",
                "status": "affected",
                "version": "6.2.9200.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2012 (Server Core installation)",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "6.2.9200.25368",
                "status": "affected",
                "version": "6.2.9200.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2012 R2",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "6.3.9600.22470",
                "status": "affected",
                "version": "6.3.9600.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2012 R2 (Server Core installation)",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "6.3.9600.22470",
                "status": "affected",
                "version": "6.3.9600.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2016",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.14393.7876",
                "status": "affected",
                "version": "10.0.14393.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2016 (Server Core installation)",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.14393.7876",
                "status": "affected",
                "version": "10.0.14393.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2019",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.17763.7009",
                "status": "affected",
                "version": "10.0.17763.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2019 (Server Core installation)",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.17763.7009",
                "status": "affected",
                "version": "10.0.17763.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2022",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.20348.3328",
                "status": "affected",
                "version": "10.0.20348.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2022, 23H2 Edition (Server Core installation)",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.25398.1486",
                "status": "affected",
                "version": "10.0.25398.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2025",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.26100.3476",
                "status": "affected",
                "version": "10.0.26100.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2025 (Server Core installation)",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.26100.3476",
                "status": "affected",
                "version": "10.0.26100.0",
                "versionType": "custom"
              }
            ]
          }
        ],
        "source": "secure@microsoft.com"
      }
    ],
    "cisaActionDue": "2025-04-01",
    "cisaExploitAdd": "2025-03-11",
    "cisaRequiredAction": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
    "cisaVulnerabilityName": "Microsoft Windows NTFS Heap-Based Buffer Overflow Vulnerability",
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:o:microsoft:windows_10_1507:*:*:*:*:*:*:x64:*",
                "matchCriteriaId": "6997DE6E-CBAD-4690-A68C-8F10E477DCC2",
                "versionEndExcluding": "10.0.10240.20947",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_10_1507:*:*:*:*:*:*:x86:*",
                "matchCriteriaId": "3CBCF6D9-5085-473C-82F5-98BC246A9C4C",
                "versionEndExcluding": "10.0.10240.20947",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x64:*",
                "matchCriteriaId": "0CF0E174-4692-4AA3-B72E-12E73A1BDBE5",
                "versionEndExcluding": "10.0.14393.7876",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x86:*",
                "matchCriteriaId": "340EF5F8-D4F5-4AD8-9D80-1DEC2F376BE5",
                "versionEndExcluding": "10.0.14393.7876",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x64:*",
                "matchCriteriaId": "67C8DCD7-90C4-431F-BD03-FDFDE170E748",
                "versionEndExcluding": "10.0.17763.7009",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x86:*",
                "matchCriteriaId": "05169574-28AB-4E42-B3DE-710574BB1AD3",
                "versionEndExcluding": "10.0.17763.7009",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:arm64:*",
                "matchCriteriaId": "714C0D5E-BE31-45AB-A729-FF55DE59F593",
                "versionEndExcluding": "10.0.19044.5608",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:x64:*",
                "matchCriteriaId": "0C8B2D45-7059-4FA0-A46C-64A171D287DA",
                "versionEndExcluding": "10.0.19044.5608",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:x86:*",
                "matchCriteriaId": "5569800D-B907-47CC-86D2-EC0118157916",
                "versionEndExcluding": "10.0.19044.5608",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:arm64:*",
                "matchCriteriaId": "A84E706C-3A65-4920-8F80-2A684D3CB110",
                "versionEndExcluding": "10.0.19045.5608",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:x64:*",
                "matchCriteriaId": "ED157557-37C1-4802-8746-B87120BA16FA",
                "versionEndExcluding": "10.0.19045.5608",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:x86:*",
                "matchCriteriaId": "BE8F0EF2-EED3-4791-AE26-D24D97B673D6",
                "versionEndExcluding": "10.0.19045.5608",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_11_22h2:*:*:*:*:*:*:arm64:*",
                "matchCriteriaId": "C8949B3E-5847-42F8-A15A-D7515F0EE305",
                "versionEndExcluding": "10.0.22621.5039",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_11_22h2:*:*:*:*:*:*:x64:*",
                "matchCriteriaId": "84D4F97D-3BA2-4B7A-B650-5772DE49CE97",
                "versionEndExcluding": "10.0.22621.5039",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:arm64:*",
                "matchCriteriaId": "82807292-1736-4453-B805-3D471BF94A35",
                "versionEndExcluding": "10.0.22631.5039",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:x64:*",
                "matchCriteriaId": "E19130AD-ECD6-4FC4-B2C8-AB058BDEF928",
                "versionEndExcluding": "10.0.22631.5039",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:arm64:*",
                "matchCriteriaId": "B7ADF37E-1DD3-4539-8922-1E059955FEF1",
                "versionEndExcluding": "10.0.26100.3403",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:x64:*",
                "matchCriteriaId": "E0A74D52-ABC0-4733-B892-F8688B6AEBA7",
                "versionEndExcluding": "10.0.26100.3403",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_server_2008:-:sp2:*:*:*:*:x64:*",
                "matchCriteriaId": "2127D10C-B6F3-4C1D-B9AA-5D78513CC996",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_server_2008:-:sp2:*:*:*:*:x86:*",
                "matchCriteriaId": "AB425562-C0A0-452E-AABE-F70522F15E1A",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:x64:*",
                "matchCriteriaId": "AF07A81D-12E5-4B1D-BFF9-C8D08C32FF4F",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*",
                "matchCriteriaId": "A7DF96F8-BA6A-4780-9CA3-F719B3F81074",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*",
                "matchCriteriaId": "DB18C4CE-5917-401E-ACF7-2747084FD36E",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_server_2016:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "C7610CDB-A02B-4C62-B17F-6DCE2B3DE4F0",
                "versionEndExcluding": "10.0.14393.7876",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_server_2019:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "D271422D-A29F-4DBF-BF72-BCD90E393A5A",
                "versionEndExcluding": "10.0.17763.7009",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_server_2022:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "AAACC9C4-DDC5-4059-AFE3-A49DB2347A86",
                "versionEndExcluding": "10.0.20348.3270",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_server_2022_23h2:*:*:*:*:*:*:x64:*",
                "matchCriteriaId": "96046A7B-76A1-4DCF-AEA5-25344D37E492",
                "versionEndExcluding": "10.0.25398.1486",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:x64:*",
                "matchCriteriaId": "CE542697-31D8-4EC2-8135-F0468431FD19",
                "versionEndExcluding": "10.0.26100.3403",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally."
      },
      {
        "lang": "es",
        "value": "El desbordamiento del búfer basado en montón en Windows NTFS permite que un atacante no autorizado ejecute código localmente."
      }
    ],
    "id": "CVE-2025-24993",
    "lastModified": "2026-09-24T13:10:00.320",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "HIGH",
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 1.8,
          "impactScore": 5.9,
          "source": "secure@microsoft.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-24993",
            "options": [
              {
                "exploitation": "active"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2025-03-14T03:55:33.583406Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2025-03-11T17:16:35.797",
    "references": [
      {
        "source": "secure@microsoft.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-24993"
      },
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "tags": [
          "US Government Resource"
        ],
        "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-24993"
      }
    ],
    "sourceIdentifier": "secure@microsoft.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-122"
          }
        ],
        "source": "secure@microsoft.com",
        "type": "Secondary"
      }
    ]
  }
}
—
Every claim, by kind

vulnerability

Microsoft Windows NTFS Heap-Based Buffer Overflow Vulnerability
zetlyn/cve-kev · 2025-03-11
cwe CWE-122 cwes CWE-122 due_date 2025-04-01 exploited yes forensic_triage false known_ransomware_campaign_use Unknown product Windows vendor Microsoft
Microsoft Windows NTFS Heap-Based Buffer Overflow Vulnerability
zetlyn/cve-nvd · 2025-03-11
automatable no cvss 7.8 cvss_vector CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H cwe CWE-122 exploitation active fixed_in 10.0.10240.20947, 10.0.14393.7876, 10.0.17763.7009, 10.0.19044.5608, 10.0.19045.5608, 10.0.22621.5039, 10.0.22631.5039, 10.0.26100.3476, 6.1.7601.27618, 6.0.6003.23168, 6.2.9200.25368, 6.3.9600.22470, 10.0.20348.3328, 10.0.25398.1486 product Windows 10 Version 1507 severity HIGH status Analyzed technical_impact total vendor Microsoft source