ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews1

URGENT: Microsoft Patches 57 Security Flaws, Including 6 Actively Exploited Zero

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-43572
Actively Exploited RCE in Microsoft Management Console on Windows 10, 11 and Server

CVE-2024-43572 is a remote code execution vulnerability in Microsoft Management Console (MMC, mmc.exe), patched by Microsoft as an actively exploited zero-day in its October 2024 Patch Tuesday release. It is triggered when a user opens a specially crafted .msc snap-in file; the CVSS vector (AV:L/AC:L/PR:N/UI:R) confirms local delivery with user interaction, for example via a phishing attachment or downloaded file. Successful exploitation allows the attacker to execute arbitrary code in the context of the user who opened the file, with high impact on confidentiality, integrity and availability. Per the published CPE data, affected systems span Windows 10 (1507, 1607, 1809, 21H2, 22H2), Windows 11 (21H2 through 24H2) and Windows Server 2008, 2012 and 2016, effectively the entire installed Windows base. The flaw is confirmed exploited in the wild: it was added to CISA's KEV on 2024-10-08, EPSS assigns a ~67% probability of exploitation within 30 days (99th percentile), and press coverage lists it among the two exploited zero-days fixed in October 2024.

Do: Apply Microsoft's October 2024 (or later) security/cumulative updates to all affected Windows 10, Windows 11 and Windows Server systems, as the MMC fix ships in the monthly cumulative updates rather than as a standalone patch. Until patched, do not open .msc snap-in files from untrusted or unsolicited sources and brief users on malicious snap-in attachments. Track this against the KEV required action and prioritize deployment given confirmed in-the-wild exploitation and high EPSS.

7.867% KEV
  • microsoft Windows 10 1507, 1607, 1809, 21H2, 22H2
  • microsoft Windows 11 21H2, 22H2, 23H2, 24H2
  • microsoft Windows Server 2008, 2012, 2016
mass≈1+ billion Windows 10/11 devices plus widespread Windows Server 2008–2016 deployments
CVE-2025-24985
Local Code Execution via Integer Overflow in Microsoft Windows Fast FAT Driver

CVE-2025-24985 is an integer overflow (CWE-190) in the Windows Fast FAT file system driver that can lead to a buffer overflow condition (CWE-122) when the driver processes crafted FAT file system structures. Because the Fast FAT driver handles FAT-formatted storage, the flaw is triggered locally, most plausibly by mounting or interacting with a specially crafted FAT-formatted disk image or removable medium, with user interaction required per the CVSS vector. A successful exploit allows an unauthorized local attacker to execute code on the affected machine, with high impact to confidentiality, integrity, and availability (CVSS 3.1 base score 7.8, High). All Windows client versions from Windows 10 1507 through Windows 11 24H2 and Windows Server 2008/2012/2016/2019 are in the affected scope, meaning essentially any unpatched Windows system on those version lines is exposed. The flaw is being actively exploited: CISA added it to the Known Exploited Vulnerabilities catalog on 2025-03-11, Microsoft fixed it in the March 2025 Patch Tuesday release as one of six actively exploited zero-days, and EPSS currently estimates a 3.8% chance of exploitation in the next 30 days (89th percentile); ransomware use is listed as unknown.

Do: Install Microsoft's March 2025 Windows cumulative security updates on every affected Windows 10, Windows 11, and Windows Server host, and prioritize endpoints that mount untrusted removable media or disk images; federal agencies must apply the fix within the CISA BOD 22-01 deadline tied to the 2025-03-11 KEV listing. Until systems are patched, discourage or restrict use of untrusted FAT-formatted media and crafted disk images, and inventory your estate for the affected version branches (Windows 10 1507/1607/1809/21H2/22H2, Windows 11 22H2/23H2/24H2, Server 2008/2012/2016/2019). Because ransomware use is listed as unknown, treat this as a high-priority patch given active exploitation is confirmed.

7.8
group max
4% KEV PoC
  • microsoft Windows 10 1507, 1607, 1809, 21H2, 22H2
  • microsoft Windows 11 22H2, 23H2, 24H2
  • microsoft Windows Server 2008
  • +3 more
masshundreds of millions of unpatched Windows client and server systems worldwide (unknown precisely)
CVE-2025-26643
The UI performs the wrong action in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

The UI performs the wrong action in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

NVD description · AI analysis pending
5.4<1%
  • microsoft edge chromium
Full article936 words · extracted from thehackernews.com · click to collapse

Ravie LakshmananMar 12, 2025Patch Tuesday / Vulnerability

Microsoft on Tuesday released security updates to address 57 security vulnerabilities in its software, including a whopping six zero-days that it said have been actively exploited in the wild.

Of the 56 flaws, six are rated Critical, 50 are rated Important, and one is rated Low in severity. Twenty-three of the addressed vulnerabilities are remote code execution bugs and 22 relate to privilege escalation.

The updates are in addition to 17 vulnerabilities Microsoft addressed in its Chromium-based Edge browser since the release of last month's Patch Tuesday update, one of which is a spoofing flaw specific to the browser (CVE-2025-26643, CVSS score: 5.4).

The six vulnerabilities that have come under active exploitation are listed below -

  • CVE-2025-24983 (CVSS score: 7.0) - A Windows Win32 Kernel Subsystem use-after-free (UAF) vulnerability that allows an authorized attacker to elevate privileges locally
  • CVE-2025-24984 (CVSS score: 4.6) - A Windows NTFS information disclosure vulnerability that allows an attacker with physical access to a target device and the ability to plug in a malicious USB drive to potentially read portions of heap memory
  • CVE-2025-24985 (CVSS score: 7.8) - An integer overflow vulnerability in Windows Fast FAT File System Driver that allows an unauthorized attacker to execute code locally
  • CVE-2025-24991 (CVSS score: 5.5) - An out-of-bounds read vulnerability in Windows NTFS that allows an authorized attacker to disclose information locally
  • CVE-2025-24993 (CVSS score: 7.8) - A heap-based buffer overflow vulnerability in Windows NTFS that allows an unauthorized attacker to execute code locally
  • CVE-2025-26633 (CVSS score: 7.0) - An improper neutralization vulnerability in Microsoft Management Console that allows an unauthorized attacker to bypass a security feature locally

ESET, which is credited with discovering and reporting CVE-2025-24983, said it first discovered the zero-day exploit in the wild in March 2023 and delivered via a backdoor named PipeMagic on compromised hosts.

"The vulnerability is a use-after-free in Win32k driver," the Slovakian company noted. "In a certain scenario achieved using the WaitForInputIdle API, the W32PROCESS structure gets dereferenced one more time than it should, causing UAF. To reach the vulnerability, a race condition must be won."

PipeMagic, first discovered in 2022, is a plugin-based trojan that has targeted entities in Asia and Saudi Arabia, with the malware distributed in the form of a fake OpenAI ChatGPT application in late 2024 campaigns.

"One of unique features of PipeMagic is that it generates a 16-byte random array to create a named pipe in the format \\.\pipe\1.<hex string>," Kaspersky revealed in October 2024. "It spawns a thread that continuously creates this pipe, reads data from it, and then destroys it."

"This pipe is used for receiving encoded payloads, stop signals via the default local interface. PipeMagic usually works with multiple plugins downloaded from a command-and-control (C2) server, which, in this case, was hosted on Microsoft Azure."

The Zero Day Initiative noted that CVE-2025-26633 stems from how MSC files are handled, allowing an attacker to evade file reputation protections and execute code in the context of the current user. The activity has been linked to a threat actor tracked as EncryptHub (aka LARVA-208).

Action1 pointed out that threat actors could chain the four vulnerabilities affecting core Windows file system components to cause remote code execution (CVE-2025-24985 and CVE-2025-24993) and information disclosure (CVE-2025-24984 and CVE-2025-24991). All the four bugs were reported anonymously.

"Specifically, the exploit relies on the attacker crafting a malicious VHD file and convincing a user to open or mount a VHD file," Kev Breen, senior director of threat research at Immersive, said. "VHDs are Virtual Hard Disks and are typically associated with storing the operating system for virtual machines."

"Whilst they are more typically associated with Virtual Machines, we have seen examples over the years where threat actors use VHD or VHDX files as part of phishing campaigns to smuggle malware payloads past AV solutions. Depending on the configuration of Windows systems, simply double-clicking on a VHD file could be enough to mount the container and, therefore, execute any payloads contained within the malicious file."

According to Satnam Narang, senior staff research engineer at Tenable, CVE-2025-26633 is the second flaw in MMC to be exploited in the wild as a zero-day after CVE-2024-43572 and CVE-2025-24985 is the first vulnerability in the Windows Fast FAT File System Driver since March 2022. It's also the first to be exploited in the wild as a zero-day.

As is customary, it's currently not known the remaining vulnerabilities are being exploited, in what context, and the exact scale of the attacks. The development has prompted the U.S. Cybersecurity and Infrastructure Security Agency (CISA) to add them to the Known Exploited Vulnerabilities (KEV) catalog, requiring federal agencies to apply the fixes by April 1, 2025.

Software Patches from Other Vendors

In addition to Microsoft, security updates have also been released by other vendors over the past several weeks to rectify several vulnerabilities, including —

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2025/03/urgent-microsoft-patches-57-security.html