News Score: Score the News, Sort the News, Rewrite the Headlines

Buried in the Log. Exploiting a 20 years old NTFS Vulnerability

Intro Filesystems implementation is old complex and not very well audited by independent researchers. In this article I would like to share beautiful exploitation showcase of vulnerability that I found in Windows NTFS implementation. This vulnerabilty, CVE-2025-49689, is reachable through specific crafted virtual disk (VHD). Adversaries use Virtual Disks in their phishing companies as containers for their malicious payloads. From user perspective Virtual Disk is just a container with files like ...

Read more at swarm.ptsecurity.com

© News Score  score the news, sort the news, rewrite the headlines