ThreatCluster

Microsoft Addresses CVEs in NTFS3 File System Vulnerabilities

First seen 18 Feb 2026, 11:17 UTC Api.Msrc.Microsoft 41

Article Content

Browse articles
ThreatCluster

Microsoft has published information on two vulnerabilities in the NTFS3 file system. CVE-2024-27407, published on May 17, 2024, involves a fixed overflow check in the function mi_enum_attr(). CVE-2024-52560, published on February 27, 2025, marks an inode as bad when an error is detected in the same function.

Timeline

2024-05-17
CVE-2024-27407 published
2025-02-27
CVE-2024-52560 published
2026-02-18
Information published on CVE-2024-27407 and CVE-2024-52560