Microsoft Windows NTFS Information Disclosure Vulnerability
Vendor: Microsoft
Product: Windows
Added: 2025-03-11
Due Date: 2025-04-01
Description:
Microsoft Windows New Technology File System (NTFS) contains an insertion of sensitive Information into log file vulnerability that allows an unauthorized attacker to disclose information with a physical attack. An attacker who successfully exploited this vulnerability could potentially read portions of heap memory.
Required Action:
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CWEs: