HIGH
CVE-2025-24985
CVSS
7.8
KEV
Description
Integer overflow or wraparound in Windows Fast FAT Driver allows an unauthorized attacker to execute code locally.
Summary dbcve.org
Integer overflow in the Windows Fast FAT file system driver allows a local attacker to execute code at kernel privilege level. The vulnerability stems from improper integer arithmetic handling in the FAT driver when processing file system operations, potentially enabling a low-privileged user to escalate to SYSTEM-level code execution.
Mitigation
Apply the Microsoft security update (KB5055527 or subsequent) to all affected Windows systems. Prioritize patching systems where untrusted local users have access.
Weakness (CWE)
CWE-122
Heap-based Buffer Overflow
CWE-190
Integer Overflow
EPSS Score
3.85%
Probability of exploitation in next 30 days
89.7th percentile
References
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-24985
Patch, Vendor Advisory
https://www.vicarius.io/vsociety/posts/cve-2025-24985-integer-overflow-vulnerability-in-microsoft-windows-fast-fat-driver-detection-script
Exploit, Third Party Advisory
https://www.vicarius.io/vsociety/posts/cve-2025-24985-integer-overflow-vulnerability-in-microsoft-windows-fast-fat-driver-mitigation-script
Mitigation, Third Party Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-24985
US Government Resource
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.