Microsoft patches 57 vulnerabilities, including 6 zero
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-24035 | Sensitive data storage in improperly locked memory in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network. Sensitive data storage in improperly locked memory in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network. NVD description · AI analysis pending | 8.1 | 2% |
| — | ||
| CVE-2025-24045 | Sensitive data storage in improperly locked memory in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network. Sensitive data storage in improperly locked memory in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network. NVD description · AI analysis pending | 8.1 | 1% |
| — | ||
| CVE-2025-24985 | Local Code Execution via Integer Overflow in Microsoft Windows Fast FAT Driver CVE-2025-24985 is an integer overflow (CWE-190) in the Windows Fast FAT file system driver that can lead to a buffer overflow condition (CWE-122) when the driver processes crafted FAT file system structures. Because the Fast FAT driver handles FAT-formatted storage, the flaw is triggered locally, most plausibly by mounting or interacting with a specially crafted FAT-formatted disk image or removable medium, with user interaction required per the CVSS vector. A successful exploit allows an unauthorized local attacker to execute code on the affected machine, with high impact to confidentiality, integrity, and availability (CVSS 3.1 base score 7.8, High). All Windows client versions from Windows 10 1507 through Windows 11 24H2 and Windows Server 2008/2012/2016/2019 are in the affected scope, meaning essentially any unpatched Windows system on those version lines is exposed. The flaw is being actively exploited: CISA added it to the Known Exploited Vulnerabilities catalog on 2025-03-11, Microsoft fixed it in the March 2025 Patch Tuesday release as one of six actively exploited zero-days, and EPSS currently estimates a 3.8% chance of exploitation in the next 30 days (89th percentile); ransomware use is listed as unknown. Do: Install Microsoft's March 2025 Windows cumulative security updates on every affected Windows 10, Windows 11, and Windows Server host, and prioritize endpoints that mount untrusted removable media or disk images; federal agencies must apply the fix within the CISA BOD 22-01 deadline tied to the 2025-03-11 KEV listing. Until systems are patched, discourage or restrict use of untrusted FAT-formatted media and crafted disk images, and inventory your estate for the affected version branches (Windows 10 1507/1607/1809/21H2/22H2, Windows 11 22H2/23H2/24H2, Server 2008/2012/2016/2019). Because ransomware use is listed as unknown, treat this as a high-priority patch given active exploitation is confirmed. | 7.8 group max | 4% | KEV PoC |
| masshundreds of millions of unpatched Windows client and server systems worldwide (unknown precisely) |
Full article702 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
More than three-quarters of the vulnerabilities covered in the vendor’s monthly Patch Tuesday update are high-severity flaws.
Listen to this article
0:00
Learn more.
Microsoft patched 57 vulnerabilities affecting its foundational systems and core products, including six actively exploited zero-day vulnerabilities, the company said in its latest security update Tuesday. Four of the six zero-days, which were all added to the Cybersecurity and Infrastructure Security Agency’s known exploited vulnerabilities catalog, are high-severity on the CVSS scale.
The software defects impact fundamental drivers, kernels and dozens of products, including Microsoft Office, Windows components and multiple remote desktop services. More than three-quarters of the vulnerabilities covered in the update are high-severity flaws on the CVSS scale.
“This is now the sixth consecutive month where Microsoft has published zero-day vulnerabilities on Patch Tuesday without evaluating any of them as critical severity at time of publication,” Adam Barnett, lead software engineer at Rapid7, said in an email.
Four of the zero-day vulnerabilities affect core Windows file system components. This includes CVE-2025-24985, a combination of integer overflow and heap-based buffer overflow defects in the Windows Fast FAT File System Driver, and a trio of zero-days affecting Windows NTFS (new technology file system): a remote code execution vulnerability CVE-2025-24984, heap-based buffer overflow flaw CVE-2025-24993 and out-of-bound read defect CVE-2025-24991.
“These vulnerabilities exist in fundamental operating system drivers critical to Windows operations, making them a global security risk,” Mike Walters, president and co-founder of Action1, said in an email.
“Since these vulnerabilities allow attackers to bypass application-level security entirely, gaining kernel-level or direct memory access, they pose severe and long-term operational risks,” he said. “Their active exploitation suggests that advanced persistent threat groups and cybercriminal organizations are already leveraging them.”
Threat groups are likely privately sharing a proof of concept for CVE-2025-24984, an actively exploited vulnerability, which has a CVSS score of 4.6, according to Action1.
The remaining zero-days in Microsoft’s security update include high-severity vulnerabilities CVE-2025-26633, an improper neutralization flaw in Microsoft Management Console, and CVE-2025-24983 in Windows Win32 Kernel Subsystem.
Filip Jurčacko, a researcher at ESET who discovered the zero-day exploit cataloged as CVE-2025-24983, said the use-after-free vulnerability is related to improper memory usage during software operation. Attackers can exploit the flaw for privilege escalation on previously compromised machines and run malicious code, Jurčacko said in an email.
The vendor’s monthly release of patches addresses 10 vulnerabilities that Microsoft designates as “more likely” to be exploited. This batch of more concerning flaws includes a pair of software defects that could allow for remote code execution in Windows Remote Desktop Services — sensitive data storage in improperly locked memory vulnerabilities CVE-2025-24035 and CVE-2025-24045.
The full list of vulnerabilities addressed this month is available in Microsoft’s Security Response Center.
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Technology
Threats
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/microsoft-patch-tuesday-march-2025/