ZeroHour

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-24084
Untrusted pointer dereference in Windows Subsystem for Linux allows an unauthorized attacker to execute code locally.

Untrusted pointer dereference in Windows Subsystem for Linux allows an unauthorized attacker to execute code locally.

NVD description · AI analysis pending
8.4<1%
  • microsoft windows 11 22h2
  • microsoft windows 11 23h2
  • microsoft windows 11 24h2
  • +1 more
CVE-2025-24985
Local Code Execution via Integer Overflow in Microsoft Windows Fast FAT Driver

CVE-2025-24985 is an integer overflow (CWE-190) in the Windows Fast FAT file system driver that can lead to a buffer overflow condition (CWE-122) when the driver processes crafted FAT file system structures. Because the Fast FAT driver handles FAT-formatted storage, the flaw is triggered locally, most plausibly by mounting or interacting with a specially crafted FAT-formatted disk image or removable medium, with user interaction required per the CVSS vector. A successful exploit allows an unauthorized local attacker to execute code on the affected machine, with high impact to confidentiality, integrity, and availability (CVSS 3.1 base score 7.8, High). All Windows client versions from Windows 10 1507 through Windows 11 24H2 and Windows Server 2008/2012/2016/2019 are in the affected scope, meaning essentially any unpatched Windows system on those version lines is exposed. The flaw is being actively exploited: CISA added it to the Known Exploited Vulnerabilities catalog on 2025-03-11, Microsoft fixed it in the March 2025 Patch Tuesday release as one of six actively exploited zero-days, and EPSS currently estimates a 3.8% chance of exploitation in the next 30 days (89th percentile); ransomware use is listed as unknown.

Do: Install Microsoft's March 2025 Windows cumulative security updates on every affected Windows 10, Windows 11, and Windows Server host, and prioritize endpoints that mount untrusted removable media or disk images; federal agencies must apply the fix within the CISA BOD 22-01 deadline tied to the 2025-03-11 KEV listing. Until systems are patched, discourage or restrict use of untrusted FAT-formatted media and crafted disk images, and inventory your estate for the affected version branches (Windows 10 1507/1607/1809/21H2/22H2, Windows 11 22H2/23H2/24H2, Server 2008/2012/2016/2019). Because ransomware use is listed as unknown, treat this as a high-priority patch given active exploitation is confirmed.

7.8
group max
4% KEV PoC
  • microsoft Windows 10 1507, 1607, 1809, 21H2, 22H2
  • microsoft Windows 11 22H2, 23H2, 24H2
  • microsoft Windows Server 2008
  • +3 more
masshundreds of millions of unpatched Windows client and server systems worldwide (unknown precisely)
CVE-2025-26630
Use after free in Microsoft Office Access allows an unauthorized attacker to execute code locally.

Use after free in Microsoft Office Access allows an unauthorized attacker to execute code locally.

NVD description · AI analysis pending
7.8<1%
  • microsoft 365 apps
  • microsoft access
  • microsoft office
  • +1 more
CVE-2025-26645
Relative path traversal in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

Relative path traversal in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

NVD description · AI analysis pending
8.83%
  • microsoft windows 10 1507
  • microsoft windows 10 1607
  • microsoft windows 10 1809
  • +1 more
Full article419 words · extracted from infosecurity-magazine.com · click to collapse

Microsoft’s March Patch Tuesday has put more pressure on system administrators, with over 50 new vulnerabilities to fix including seven zero-days.

Of these seven, six are being actively exploited in the wild. They are:

  • CVE-2025-26633: A security feature bypass in Microsoft Management Console with a CVSS score of 7.0
  • CVE-2025-24993: A remote code execution (RCE) vulnerability in Windows NTFS with a CVSS score of 7.8
  • CVE-2025-24991: An information disclosure vulnerability in Windows NTFS with a CVSS score of 5.5
  • CVE-2025-24985: An RCE vulnerability in Windows Fast FAT File System Driver with a CVSS score of 7.8
  • CVE-2025-24984: An information disclosure bug in Windows NTFS with a CVSS score of 4.6
  • CVE-2025-24983: An elevation of privilege (EoP) vulnerability in Windows Win32 Kernel Subsystem with a CVSS score of 7.0

Microsoft also released details of a zero-day vulnerability which has been publicly disclosed but not yet exploited. CVE-2025-26630 is an RCE vulnerability in Microsoft Access. It has a CVSS score of 7.8, which ranks it as “important.”

“The disclosure could provide attackers with some additional information to formulate an exploit, but the lack of code samples will increase their efforts,” explained Ivanti VP of security product management, Chris Goettl. “Risk-based prioritization would indicate a slightly higher risk for a disclosure without functional code, but not enough to bump this CVE up to critical.”

In total, there were 23 EoP and 23 RCE vulnerabilities listed this month. All six “critical” rated CVEs were RCE vulnerabilities. They include CVE-2025-24084, which affects the Windows Subsystem for Linux (WSL2) kernel.

“The advisory describes multiple possible attack vectors, but in the worst case, there is no requirement for user interaction, since simply receiving a malicious email would be enough to trigger the vulnerability,” explained Rapid7 lead software engineer, Adam Barnett. “The advisory does not clarify the context of code execution, but the magic email attack vector is alarming. Patch accordingly.”

Another critical RCE bug fixed this month is CVE-2025-26645, which affects the popular remote desktop client (RDP). It could provide threat actors with an easy means of achieving lateral movement through a victim’s network, Barnett warned.

“How much do you trust the RDP server you’re about to connect to?” he asked. “An attacker in control of a malicious RDP server simply has to wait for a client vulnerable to CVE-2025-26645 to connect in order to achieve remote code execution on the client.”

Read more on Patch Tuesday: Microsoft Patches Eight Zero-Days to Start the Year

Image credit: CHERRY.JUICE / Shutterstock.com

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/microsoft-patches-seven-zerodays/