ZeroHour

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-9157
** UNSUPPORTED WHEN ASSIGNED ** A privilege escalation vulnerability in CxUIUSvc64.exe and CxUIUSvc32.exe of Synaptics audio drivers allows a local authorized a

** UNSUPPORTED WHEN ASSIGNED ** A privilege escalation vulnerability in CxUIUSvc64.exe and CxUIUSvc32.exe of Synaptics audio drivers allows a local authorized attacker to load a DLL in a privileged process. Out of an abundance of caution, this CVE ID is being assigned to better serve our customers and ensure all who are still running this product understand that the product is End-of-Life and should be removed. For more information on this, refer to the CVE Record’s reference information.

NVD description · AI analysis pending
7.8<1%
CVE-2025-26645
+3 in the same advisory: …24056 …24051 …24035
Relative path traversal in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

Relative path traversal in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

NVD description · AI analysis pending
8.8
group max
3%
  • microsoft windows 10 1507
  • microsoft windows 10 1607
  • microsoft windows 10 1809
  • +1 more
CVE-2025-24045
Sensitive data storage in improperly locked memory in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network.

Sensitive data storage in improperly locked memory in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network.

NVD description · AI analysis pending
8.11%
  • microsoft windows server 2012
  • microsoft windows server 2016
  • microsoft windows server 2019
  • +1 more
CVE-2025-24057
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

NVD description · AI analysis pending
7.8<1%
  • microsoft 365 apps
  • microsoft office
  • microsoft office long term servicing channel
CVE-2025-24064
Use after free in DNS Server allows an unauthorized attacker to execute code over a network.

Use after free in DNS Server allows an unauthorized attacker to execute code over a network.

NVD description · AI analysis pending
8.11%
  • microsoft windows server 2008
  • microsoft windows server 2012
  • microsoft windows server 2016
  • +1 more
CVE-2025-24084
Untrusted pointer dereference in Windows Subsystem for Linux allows an unauthorized attacker to execute code locally.

Untrusted pointer dereference in Windows Subsystem for Linux allows an unauthorized attacker to execute code locally.

NVD description · AI analysis pending
8.4<1%
  • microsoft windows 11 22h2
  • microsoft windows 11 23h2
  • microsoft windows 11 24h2
  • +1 more
CVE-2025-24985
Local Code Execution via Integer Overflow in Microsoft Windows Fast FAT Driver

CVE-2025-24985 is an integer overflow (CWE-190) in the Windows Fast FAT file system driver that can lead to a buffer overflow condition (CWE-122) when the driver processes crafted FAT file system structures. Because the Fast FAT driver handles FAT-formatted storage, the flaw is triggered locally, most plausibly by mounting or interacting with a specially crafted FAT-formatted disk image or removable medium, with user interaction required per the CVSS vector. A successful exploit allows an unauthorized local attacker to execute code on the affected machine, with high impact to confidentiality, integrity, and availability (CVSS 3.1 base score 7.8, High). All Windows client versions from Windows 10 1507 through Windows 11 24H2 and Windows Server 2008/2012/2016/2019 are in the affected scope, meaning essentially any unpatched Windows system on those version lines is exposed. The flaw is being actively exploited: CISA added it to the Known Exploited Vulnerabilities catalog on 2025-03-11, Microsoft fixed it in the March 2025 Patch Tuesday release as one of six actively exploited zero-days, and EPSS currently estimates a 3.8% chance of exploitation in the next 30 days (89th percentile); ransomware use is listed as unknown.

Do: Install Microsoft's March 2025 Windows cumulative security updates on every affected Windows 10, Windows 11, and Windows Server host, and prioritize endpoints that mount untrusted removable media or disk images; federal agencies must apply the fix within the CISA BOD 22-01 deadline tied to the 2025-03-11 KEV listing. Until systems are patched, discourage or restrict use of untrusted FAT-formatted media and crafted disk images, and inventory your estate for the affected version branches (Windows 10 1507/1607/1809/21H2/22H2, Windows 11 22H2/23H2/24H2, Server 2008/2012/2016/2019). Because ransomware use is listed as unknown, treat this as a high-priority patch given active exploitation is confirmed.

7.8
group max
4% KEV PoC
  • microsoft Windows 10 1507, 1607, 1809, 21H2, 22H2
  • microsoft Windows 11 22H2, 23H2, 24H2
  • microsoft Windows Server 2008
  • +3 more
masshundreds of millions of unpatched Windows client and server systems worldwide (unknown precisely)
Full article761 words · extracted from blog.talosintelligence.com · click to collapse

Tuesday, March 11, 2025 17:55

Microsoft has released its monthly security update for March of 2025 which includes 57 vulnerabilities affecting a range of products, including 6 that Microsoft marked as “critical”. 

There are six vulnerabilities that Microsoft has observed being exploited in the wild. CVE-2025-26633 is a Remoted Code Execution (RCE) vulnerability in Microsoft’s Management Console. Two information disclosure vulnerabilities, CVE-2025-24984 and CVE-2025-24991, and one RCE vulnerability, CVE-2025-24993, in Windows NTFS were observed being exploited in the wild. Microsoft also patched, CVE-2025-24985, another RCE exploited in the wild in the Windows Fast FAT system driver. An Elevation of Privilege (EOP) vulnerability, CVE-2025-24983, was also discovered being exploited in the wild, in Windows’ win32 Kernel Subsystem. 

There are two notable "critical" vulnerabilities. The first is CVE-2025-24035, which is a remote code execution (RCE) vulnerability affecting the Windows Remote Desktop Gateway (RD Gateway) service. This vulnerability is a remote unauthenticated User-after-free (UAF) issue in handling websocket initialization and closing operations which could potentially result in arbitrary code execution in the RD Gateway process. Successful exploitation of this vulnerability requires the attacker to connect to a system with the RD Gateway role. CVE-2025-24035 has been assigned a CVSS 3.1 score of 8.1 and is considered “more likely to be exploited” by Microsoft. 

CVE-2025-24045 is another critical remote code execution vulnerability in the RD Gateway service caused by a UAF issue in handling connection and disconnection callbacks. Successful exploitation of this vulnerability requires the attacker to connect to a system with the RD Gateway role. This vulnerability has also been assigned a CVSS 3.1 score of 8.1 and is considered “more likely to be exploited” by Microsoft. 

CVE-2024-9157 is an elevation of privilege vulnerability in a Synaptics Audio Effect Component service binaries DLL distributed with Windows Update. This vulnerability is caused by the Synaptics service opening a named pipe without any meaningful ACLs and expecting clients to provide the name of a DLL which is then loaded into the Synaptics process, which may allow even a remote unprivileged user to provide a malicious DLL to be loaded in the context of the service. This vulnerability has been assigned a CVSS 3.1 score of 9.9 and is considered “more likely to be exploited” by Microsoft. 

CVE-2025-24064 is an RCE vulnerability in the Windows Domain Name Service flagged as "critical” by Microsoft.  To successfully exploit this vulnerability an attacker needs to send a perfectly timed DNS update message to the vulnerable server which may cause a UAF error and could potentially lead to remote code execution. This vulnerability has been assigned a CVSS 3.1 score of 8.1 and is considered "less likely to be exploited” by Microsoft. 

CVE-2025-24084 is an RCE in the Windows Subsystem for Linux (WSL2) Kernel caused by an untrusted pointer dereference. To exploit this vulnerability an attacker needs to have elevated privileges on the target machine, due to the requirement of manipulating processes, which isn’t usually accessible by regular users. This vulnerability has been assigned a CVSS 3.1 score of 8.4 but was considered "less likely to be exploited” by Microsoft. 

CVE-2025-26645 is a vulnerability in the Remote Desktop (RDP) client caused by a relative path traversal issue. An attacker in control of a Remote Desktop Server could achieve RCE on any vulnerable client machine connecting to the service. This vulnerability has been assigned a CVSS 3.1 score of 8.8 and is considered "less likely to be exploited” by Microsoft. 

Talos would also like to highlight the following vulnerabilities that Microsoft considers to be “important” or "Critical”:     

  • CVE-2025-24057 Microsoft Office Remote Code Execution Vulnerability 
  • CVE-2025-24051 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability 
  • CVE-2025-24056 Windows Telephony Service Remote Code Execution Vulnerability 

A complete list of all the other vulnerabilities Microsoft disclosed this month is available on its update page

In response to these vulnerability disclosures, Talos is releasing a new Snort rule set that detects attempts to exploit some of them. Please note that additional rules may be released at a future date and current rules are subject to change pending additional information. Cisco Security Firewall customers should use the latest update to their ruleset by updating their SRU. Open-source Snort Subscriber Rule Set customers can stay up to date by downloading the latest rule pack available for purchase on Snort.org.   

The rules included in this release that protect against the exploitation of many of these vulnerabilities are 64663, 64662, 64432, 64658, 64659, 64656, 64657, 64660, 64661, 64653, 64652. There are also these Snort 3 rules: 64432, 301166, 301164, 301163, 301165, 301162 

Text extracted automatically; images, tables and formatting may be missing. Original: https://blog.talosintelligence.com/march-patch-tuesday-release/