PT-2025-10830 · Microsoft · Windows Fast Fat Driver +1
Oruga
·
Published
2025-03-11
·
Updated
2025-07-17
·
CVE-2025-24985
Oruga
·
Published
2025-03-11
·
Updated
2025-07-17
·
CVE-2025-24985
7.8
High
Base vector | Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
**Name of the Vulnerable Software and Affected Versions:**
Microsoft Windows versions prior to the March 2025 security update.
**Description:**
An integer overflow or wraparound vulnerability exists in the Windows Fast FAT File System Driver. This flaw allows an unauthorized attacker to execute code locally. The vulnerability has been actively exploited in the wild, with threat actors utilizing a backdoor named PipeMagic. Exploitation requires user interaction, such as tricking users into mounting malicious VHD files. The vulnerability can allow remote attackers to execute arbitrary code and affect the system.
**Recommendations:**
Apply the March 2025 security update to mitigate this vulnerability.
Exploit
Fix
RCE
LPE
Buffer Overflow
Heap Based Buffer Overflow
Integer Overflow