CVE CVE

CVE-2025-24985

CISA Known Exploited Vulnerability (KEV)

Microsoft Windows Fast FAT File System Driver Integer Overflow Vulnerability

March 11, 2025

April 1, 2025

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Description

Integer overflow or wraparound in Windows Fast FAT Driver allows an unauthorized attacker to execute code locally.

Weakness Enumeration

CWE-ID CWE Name

CWE-122
Heap-based Buffer Overflow

Details

Source:
NVD
Published:
Updated:

Risk information

CVSS v3

Base score:
7.8
Severity:

HIGH

Vector:
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CVSS v2

Not defined