ZeroHour
CyberScooppublished ()ingested @CyberScoopNews

Microsoft patches 57 vulnerabilities, including 6 zero

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-24035
Sensitive data storage in improperly locked memory in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network.

Sensitive data storage in improperly locked memory in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network.

NVD description · AI analysis pending
8.12%
  • microsoft windows 10 1507
  • microsoft windows 10 1607
  • microsoft windows 10 1809
  • +1 more
CVE-2025-24045
Sensitive data storage in improperly locked memory in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network.

Sensitive data storage in improperly locked memory in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network.

NVD description · AI analysis pending
8.11%
  • microsoft windows server 2012
  • microsoft windows server 2016
  • microsoft windows server 2019
  • +1 more
CVE-2025-24985
Local Code Execution via Integer Overflow in Microsoft Windows Fast FAT Driver

CVE-2025-24985 is an integer overflow (CWE-190) in the Windows Fast FAT file system driver that can lead to a buffer overflow condition (CWE-122) when the driver processes crafted FAT file system structures. Because the Fast FAT driver handles FAT-formatted storage, the flaw is triggered locally, most plausibly by mounting or interacting with a specially crafted FAT-formatted disk image or removable medium, with user interaction required per the CVSS vector. A successful exploit allows an unauthorized local attacker to execute code on the affected machine, with high impact to confidentiality, integrity, and availability (CVSS 3.1 base score 7.8, High). All Windows client versions from Windows 10 1507 through Windows 11 24H2 and Windows Server 2008/2012/2016/2019 are in the affected scope, meaning essentially any unpatched Windows system on those version lines is exposed. The flaw is being actively exploited: CISA added it to the Known Exploited Vulnerabilities catalog on 2025-03-11, Microsoft fixed it in the March 2025 Patch Tuesday release as one of six actively exploited zero-days, and EPSS currently estimates a 3.8% chance of exploitation in the next 30 days (89th percentile); ransomware use is listed as unknown.

Do: Install Microsoft's March 2025 Windows cumulative security updates on every affected Windows 10, Windows 11, and Windows Server host, and prioritize endpoints that mount untrusted removable media or disk images; federal agencies must apply the fix within the CISA BOD 22-01 deadline tied to the 2025-03-11 KEV listing. Until systems are patched, discourage or restrict use of untrusted FAT-formatted media and crafted disk images, and inventory your estate for the affected version branches (Windows 10 1507/1607/1809/21H2/22H2, Windows 11 22H2/23H2/24H2, Server 2008/2012/2016/2019). Because ransomware use is listed as unknown, treat this as a high-priority patch given active exploitation is confirmed.

7.8
group max
4% KEV PoC
  • microsoft Windows 10 1507, 1607, 1809, 21H2, 22H2
  • microsoft Windows 11 22H2, 23H2, 24H2
  • microsoft Windows Server 2008
  • +3 more
masshundreds of millions of unpatched Windows client and server systems worldwide (unknown precisely)
Full article702 words · extracted from cyberscoop.com · click to collapse
Skip to main content

Get our latest cybersecurity news first on Google.

Click here!

More than three-quarters of the vulnerabilities covered in the vendor’s monthly Patch Tuesday update are high-severity flaws.

Listen to this article

0:00

Learn more.

A view of the Microsoft corporate logo in front of the Microsoft Office building on 41st street and 8th avenue on July 19, 2024 in New York City. (Photo by Craig T Fruchtman/Getty Images)

Microsoft patched 57 vulnerabilities affecting its foundational systems and core products, including six actively exploited zero-day vulnerabilities, the company said in its latest security update Tuesday. Four of the six zero-days, which were all added to the Cybersecurity and Infrastructure Security Agency’s known exploited vulnerabilities catalog, are high-severity on the CVSS scale. 

The software defects impact fundamental drivers, kernels and dozens of products, including Microsoft Office, Windows components and multiple remote desktop services. More than three-quarters of the vulnerabilities covered in the update are high-severity flaws on the CVSS scale.

“This is now the sixth consecutive month where Microsoft has published zero-day vulnerabilities on Patch Tuesday without evaluating any of them as critical severity at time of publication,” Adam Barnett, lead software engineer at Rapid7, said in an email.

Four of the zero-day vulnerabilities affect core Windows file system components. This includes CVE-2025-24985, a combination of integer overflow and heap-based buffer overflow defects in the Windows Fast FAT File System Driver, and a trio of zero-days affecting Windows NTFS (new technology file system): a remote code execution vulnerability CVE-2025-24984, heap-based buffer overflow flaw CVE-2025-24993 and out-of-bound read defect CVE-2025-24991

“These vulnerabilities exist in fundamental operating system drivers critical to Windows operations, making them a global security risk,” Mike Walters, president and co-founder of Action1, said in an email. 

“Since these vulnerabilities allow attackers to bypass application-level security entirely, gaining kernel-level or direct memory access, they pose severe and long-term operational risks,” he said. “Their active exploitation suggests that advanced persistent threat groups and cybercriminal organizations are already leveraging them.”

Threat groups are likely privately sharing a proof of concept for CVE-2025-24984, an actively exploited vulnerability, which has a CVSS score of 4.6, according to Action1.

The remaining zero-days in Microsoft’s security update include high-severity vulnerabilities CVE-2025-26633, an improper neutralization flaw in Microsoft Management Console, and CVE-2025-24983 in Windows Win32 Kernel Subsystem.

Filip Jurčacko, a researcher at ESET who discovered the zero-day exploit cataloged as CVE-2025-24983, said the use-after-free vulnerability is related to improper memory usage during software operation. Attackers can exploit the flaw for privilege escalation on previously compromised machines and run malicious code, Jurčacko said in an email.

The vendor’s monthly release of patches addresses 10 vulnerabilities that Microsoft designates as “more likely” to be exploited. This batch of more concerning flaws includes a pair of software defects that could allow for remote code execution in Windows Remote Desktop Services — sensitive data storage in improperly locked memory vulnerabilities CVE-2025-24035 and CVE-2025-24045.

The full list of vulnerabilities addressed this month is available in Microsoft’s Security Response Center.

Latest Podcasts

Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/microsoft-patch-tuesday-march-2025/