CVE-2025-21197

Improper access control in Windows NTFS allows an authorized attacker to disclose file path information under a folder where the attacker doesn't have permission to list content.

  • Published Apr 8, 2025
  • CVSS 6.5 medium
  • 3.2% chance of exploitation in the next 30 days (EPSS)

Affected software

In the news

CVE-2025-21197 at the National Vulnerability Database