CVE-2025-2489: Ntfs Tool

Medium severity, CVSS 6.8. EPSS: 0.2% chance of exploitation in the next 30 days.

Insecure information storage vulnerability in NTFS Tools version 3.5.1. Exploitation of this vulnerability could allow an attacker to know the application password, stored in /Users/user/Library/Application Support/ntfs-tool/config.json.

Affected products

Published 2025-03-18. Last modified 2026-06-17.