HIGH

CVE-2025-24985

Microsoft Windows 10 1507 2025-03-11 CVSS v3.1
CVSS
7.8
KEV

Description

Integer overflow or wraparound in Windows Fast FAT Driver allows an unauthorized attacker to execute code locally.

Summary dbcve.org

Integer overflow in the Windows Fast FAT file system driver allows a local attacker to execute code at kernel privilege level. The vulnerability stems from improper integer arithmetic handling in the FAT driver when processing file system operations, potentially enabling a low-privileged user to escalate to SYSTEM-level code execution.

Mitigation

Apply the Microsoft security update (KB5055527 or subsequent) to all affected Windows systems. Prioritize patching systems where untrusted local users have access.

Proof of Concept
Patch Commit

Weakness (CWE)

CWE-122 Heap-based Buffer Overflow
CWE-190 Integer Overflow

EPSS Score

3.85%
Probability of exploitation in next 30 days
89.7th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE