CVE-2025-2489

March 18, 2025, 12:15 p.m.

None
No Score

Description

Insecure information storage vulnerability in NTFS Tools version 3.5.1. Exploitation of this vulnerability could allow an attacker to know the application password, stored in /Users/user/Library/Application Support/ntfs-tool/config.json.

Product(s) Impacted

Vendor Product Versions
Ntfs-tools
  • Ntfs Tools
  • 3.5.1

Weaknesses

Common security weaknesses mapped to this vulnerability.

CWE-922
Insecure Storage of Sensitive Information
The product stores sensitive information without properly limiting read or write access by unauthorized actors.

*CPE(s)

Affected systems and software identified for this CVE.

Type Vendor Product Version Update Edition Language Software Edition Target Software Target Hardware Other Information
a ntfs-tools ntfs_tools 3.5.1 / / / / / / /

Timeline

Published: March 18, 2025, 12:15 p.m.
Last Modified: March 18, 2025, 12:15 p.m.

Status : Received

CVE has been recently published to the CVE List and has been received by the NVD.

More info

Source

cve-coordination@incibe.es

*Disclaimer: Some vulnerabilities do not have an associated CPE. To enhance the data, we use AI to infer CPEs based on CVE details. This is an automated process and might not always be accurate.