ZeroHour
Security Affairspublished ()ingested @securityaffairs

Microsoft Patch Tuesday security updates for March 2025 fix six actively exploited zero

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-24985
Local Code Execution via Integer Overflow in Microsoft Windows Fast FAT Driver

CVE-2025-24985 is an integer overflow (CWE-190) in the Windows Fast FAT file system driver that can lead to a buffer overflow condition (CWE-122) when the driver processes crafted FAT file system structures. Because the Fast FAT driver handles FAT-formatted storage, the flaw is triggered locally, most plausibly by mounting or interacting with a specially crafted FAT-formatted disk image or removable medium, with user interaction required per the CVSS vector. A successful exploit allows an unauthorized local attacker to execute code on the affected machine, with high impact to confidentiality, integrity, and availability (CVSS 3.1 base score 7.8, High). All Windows client versions from Windows 10 1507 through Windows 11 24H2 and Windows Server 2008/2012/2016/2019 are in the affected scope, meaning essentially any unpatched Windows system on those version lines is exposed. The flaw is being actively exploited: CISA added it to the Known Exploited Vulnerabilities catalog on 2025-03-11, Microsoft fixed it in the March 2025 Patch Tuesday release as one of six actively exploited zero-days, and EPSS currently estimates a 3.8% chance of exploitation in the next 30 days (89th percentile); ransomware use is listed as unknown.

Do: Install Microsoft's March 2025 Windows cumulative security updates on every affected Windows 10, Windows 11, and Windows Server host, and prioritize endpoints that mount untrusted removable media or disk images; federal agencies must apply the fix within the CISA BOD 22-01 deadline tied to the 2025-03-11 KEV listing. Until systems are patched, discourage or restrict use of untrusted FAT-formatted media and crafted disk images, and inventory your estate for the affected version branches (Windows 10 1507/1607/1809/21H2/22H2, Windows 11 22H2/23H2/24H2, Server 2008/2012/2016/2019). Because ransomware use is listed as unknown, treat this as a high-priority patch given active exploitation is confirmed.

7.8
group max
4% KEV PoC
  • microsoft Windows 10 1507, 1607, 1809, 21H2, 22H2
  • microsoft Windows 11 22H2, 23H2, 24H2
  • microsoft Windows Server 2008
  • +3 more
masshundreds of millions of unpatched Windows client and server systems worldwide (unknown precisely)
Full article377 words · extracted from securityaffairs.com · click to collapse

Microsoft Patch Tuesday security updates for March 2025 address 56 security vulnerabilities in its products, including six actively exploited zero-days.

Microsoft Patch Tuesday security updates for March 2025 addressed 56 vulnerabilities in Windows and Windows Components, Office and Office Components, Azure, .NET and Visual Studio, Remote Desktop Services, DNS Server, and Hyper-V Server.

This Patch Tuesday stands out for the number of actively exploited zero-day vulnerabilities addressed by the IT giant, which totals six.

Six vulnerabilities are rated Critical, and 50 are rated Important in severity.

“Of the patches released today, six are rated Critical, and 50 are rated Important in severity. This is nearly identical to the release last month in volume, but the number of actively exploited bugs is extraordinary.” reported ZDI. “One of these bugs is listed as publicly known, and six(!) others are listed as under active attack at the time of release”

The six vulnerabilities that have been actively exploited in the wild are:

  • CVE-2025-24983 (CVSS 7.0): A use-after-free vulnerability in the Windows Win32 Kernel Subsystem that enables authorized attackers to escalate privileges locally.
  • CVE-2025-24984 (CVSS 4.6): An NTFS information disclosure flaw that lets attackers with physical access and a malicious USB device read portions of heap memory.
  • CVE-2025-24985 (CVSS 7.8): An integer overflow in the Windows Fast FAT File System Driver allowing unauthorized local code execution.
  • CVE-2025-24991 (CVSS 5.5): An out-of-bounds read vulnerability in NTFS that permits authorized attackers to access sensitive information.
  • CVE-2025-24993 (CVSS 7.8): A heap-based buffer overflow in NTFS that allows unauthorized local code execution.
  • CVE-2025-26633 (CVSS 7.0): An improper neutralization flaw in Microsoft Management Console that lets unauthorized attackers bypass security features locally.

ESET researchers, who discovered the vulnerability CVE-2025-24983, reported that the zero-day CVE-2025-24983 has been exploited since March 2023. The flaw enables attackers with low privileges to escalate to SYSTEM privileges but requires winning a race condition. The exploit, linked to the PipeMagic backdoor, has targeted unsupported Windows versions like Server 2012 R2 and 8.1 but also affects Windows 10 (build 1809 and earlier) and Server 2016.

The full list of vulnerabilities addressed by Microsoft Patch Tuesday security updates for March 2025 is available here.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Microsoft Patch Tuesday)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/175289/hacking/microsoft-patch-tuesday-security-updates-for-march-2025.html