Improper access control in Windows NTFS allows an authorized attacker to disclose file path information under a folder where the attacker doesn’t have permission to list content.
CVE-2025-21197 Windows NTFS Information Disclosure Vulnerability
Published April 8, 2025