← back
CVE-2025-24985

Windows Fast FAT File System Driver Remote Code Execution Vulnerability

CVSS 7.8 HIGHEPSS 3.7%● KEVCWE-122CWE-190
Vexday Risk Score
71High priority
SSVC decision (CISA)
Act
Exploitation + impact → act immediately
CVSS 7.8EPSS 3.7%KEV simPoC públicaNuclei Metasploit Patch referenciado
Lifecycle
11 Mar 2025Active exploitation (CISA KEV)
11 Mar 2025Published on NVD
02 Apr 2025Public PoC
Recommendation: Patch as soon as possible — active exploitation confirmed.
In short

A flaw in Windows' FAT file system driver allows an attacker to execute malicious code on a computer through a specially crafted file. This happens because the driver doesn't properly check numeric values, which can cause it to allocate memory incorrectly.

Technical detail

An integer overflow vulnerability in the Windows Fast FAT Driver (CWE-122, CWE-190) enables local code execution when processing malformed FAT filesystem structures. The vulnerability requires local file system access but no user interaction, allowing an authenticated attacker to trigger memory corruption and achieve arbitrary code execution with elevated privileges.

Summary generated and translated by AI from the official description.
Integer overflow or wraparound in Windows Fast FAT Driver allows an unauthorized attacker to execute code locally.
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →