CVE-2025-24993High· 7.8▾ Abyssal⚠ Exploited in the wild0dayHeap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.
▾ Abyssal zone — Critical with a public exploit or in-the-wild use
impact 42.9 · likelihood 0.4 · exploitation 25
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Federal remediation due Apr 1, 2025
Last analysed / modified upstream
2.2%
Added to the CISA catalog on Mar 11, 2025. Federal remediation due Apr 1, 2025. View catalog ↗
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.
windows_10_1507 < 10.0.10240.20947windows_10_1607 < 10.0.14393.7876windows_10_1809 < 10.0.17763.7009windows_10_21h2 < 10.0.19044.5608windows_10_22h2 < 10.0.19045.5608windows_11_22h2 < 10.0.22621.5039windows_11_23h2 < 10.0.22631.5039windows_11_24h2 < 10.0.26100.3403windows_server_2008windows_server_2008 = r2windows_server_2012windows_server_2012 = r2windows_server_2016 < 10.0.14393.7876windows_server_2019 < 10.0.17763.7009windows_server_2022 < 10.0.20348.3270windows_server_2022_23h2 < 10.0.25398.1486windows_server_2025 < 10.0.26100.3403Upgrade past the affected range:
windows_10_1507 10.0.10240.20947windows_10_1607 10.0.14393.7876windows_10_1809 10.0.17763.7009windows_10_21h2 10.0.19044.5608windows_10_22h2 10.0.19045.5608windows_11_22h2 10.0.22621.5039windows_11_23h2 10.0.22631.5039windows_11_24h2 10.0.26100.3403windows_server_2016 10.0.14393.7876windows_server_2019 10.0.17763.7009windows_server_2022 10.0.20348.3270windows_server_2022_23h2 10.0.25398.1486windows_server_2025 10.0.26100.3403Connected by shared product, vendor, weakness, or advisory.
CVE-2023-23376High· 7.8Windows Common Log File System Driver Elevation of Privilege Vulnerability
CVE-2025-21391High· 7.1Windows Storage Elevation of Privilege Vulnerability
CVE-2016-7255High· 7.8The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allow local…
CVE-2022-37969High· 7.8Windows Common Log File System Driver Elevation of Privilege Vulnerability
CVE-2026-85880High· 7.8Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges locally.
CVE-2021-43226High· 7.8Windows Common Log File System Driver Elevation of Privilege Vulnerability