PT-2025-10830 · Microsoft · Windows Fast Fat Driver +1

Oruga

·

Published

2025-03-11

·

Updated

2025-07-17

·

CVE-2025-24985

CVSS v3.1
7.8
VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

**Name of the Vulnerable Software and Affected Versions:**

Microsoft Windows versions prior to the March 2025 security update.

**Description:**

An integer overflow or wraparound vulnerability exists in the Windows Fast FAT File System Driver. This flaw allows an unauthorized attacker to execute code locally. The vulnerability has been actively exploited in the wild, with threat actors utilizing a backdoor named PipeMagic. Exploitation requires user interaction, such as tricking users into mounting malicious VHD files. The vulnerability can allow remote attackers to execute arbitrary code and affect the system.

**Recommendations:**

Apply the March 2025 security update to mitigate this vulnerability.

Exploit

Fix

RCE

LPE

Buffer Overflow

Heap Based Buffer Overflow

Integer Overflow

Weakness Enumeration

Related Identifiers

BDU:2025-02623
CVE-2025-24985

Affected Products

Windows
Windows Fast Fat Driver