Improper Access Control in Windows NTFS by Microsoft
CVE-2025-21197
Key Information:
- Vendor
Microsoft
- Status
- Vendor
- CVE Published:
- 8 April 2025
What is CVE-2025-21197?
A vulnerability exists in Windows NTFS where improper access control mechanisms could allow an authorized attacker to disclose sensitive file path information within a folder. This disclosure occurs even if the attacker does not have permission to list the contents of that folder, potentially leading to further exploitation and unauthorized access to secured files.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Windows 10 Version 1507 32-bit Systems 10.0.10240.0 < 10.0.10240.20978
Windows 10 Version 1607 32-bit Systems 10.0.14393.0 < 10.0.14393.7969
Windows 10 Version 1809 32-bit Systems 10.0.17763.0 < 10.0.17763.7136
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved