NVD disclosure day

Published threat advisories for March 11, 2025

CVE advisoryKnown Exploit

CVE-2025-24201

Apple Software Vulnerability Allows Web Content Evasion

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A WebKit vulnerability allows malicious web content to escape security sandboxes on Apple devices. This could lead to unauthorized actions impacting affected organizations and their data. Prompt application of vendor updates is recommended to mitigate business risk.

• CISA KEV

CVE advisoryKnown Exploit

CVE-2025-26633

Microsoft Windows Management Console Security Bypass Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A security flaw in the Microsoft Management Console allows local attackers to bypass security features, potentially impacting data confidentiality, integrity, and availability. This poses a risk to affected Windows systems.

• CISA KEV

CVE advisoryKnown Exploit

CVE-2025-24993

Windows NTFS Heap Buffer Overflow Leading to Local Code Execution

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in Windows NTFS allows local attackers to execute code, potentially compromising systems and data. Affected organizations face business risk from unauthorized access and control of local systems. Prioritizing remediation is advised.

• CISA KEV

CVE advisoryKnown Exploit

CVE-2025-24991

Microsoft Windows NTFS Information Disclosure Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in Windows NTFS allows an authorized local attacker to read sensitive information. This impacts data confidentiality and poses a business risk. The exposure is classified as internal, meaning an attacker requires existing system access.

• CISA KEV

CVE advisoryKnown Exploit

CVE-2025-24985

Windows Fast FAT Driver Local Code Execution Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An integer overflow in the Windows Fast FAT driver allows an unauthorized local attacker to execute code. This impacts systems running affected Windows versions, posing a risk of unauthorized access and modification of data, and could compromise system integrity.

• CISA KEV

CVE advisoryKnown Exploit

CVE-2025-24984

Microsoft Windows NTFS Log File Information Disclosure Advisory

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in Windows NTFS allows an attacker with physical access to disclose sensitive information from log files. This impacts organizations by potentially exposing confidential data, posing a risk to data privacy and integrity.

• CISA KEV

CVE advisoryKnown Exploit

CVE-2025-24983

Windows Kernel Privilege Escalation Vulnerability.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in the Windows Win32 Kernel Subsystem allows an authorized local attacker to elevate privileges, potentially impacting system control and data integrity. This risk necessitates prompt remediation to protect organizational assets.

• CISA KEV

CVE advisoryKnown Exploit

CVE-2025-24054

Windows NTLM Network Spoofing Vulnerability

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A network spoofing vulnerability in Windows NTLM allows unauthorized attackers to manipulate file names or paths. This could lead to unauthorized actions and potential data breaches within affected organizations. The business risk is associated with the potential for attackers to impersonate legitimate users over a net

• CISA KEV

CVE advisoryKnown Exploit

CVE-2025-27363

FreeType Font Parsing Vulnerability Allows Code Execution.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A vulnerability in the FreeType library allows for arbitrary code execution when processing specific font files. This could impact organizations by compromising systems and leading to data breaches. Business risk is elevated as this flaw may already be exploited in the wild.

• CISA KEV

CVE advisoryKnown Exploit

CVE-2024-54085

AMI MegaRAC SPx Remote Authentication Bypass Advisory

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A vulnerability in AMI's SPx allows remote attackers to bypass authentication on server management interfaces, potentially leading to data loss or system compromise. Organizations using affected systems should prioritize applying vendor updates and restricting network access to the management interface. The risk to bus

• CISA KEV