← back
CVE-2025-24985

Windows Fast FAT File System Driver Remote Code Execution Vulnerability

CVSS 7.8 HIGHEPSS 3.7%● KEVCWE-122CWE-190
In short

A flaw in Windows' FAT file system driver allows an attacker to execute malicious code on a computer through a specially crafted file. This happens because the driver doesn't properly check numeric values, which can cause it to allocate memory incorrectly.

Technical detail

An integer overflow vulnerability in the Windows Fast FAT Driver (CWE-122, CWE-190) enables local code execution when processing malformed FAT filesystem structures. The vulnerability requires local file system access but no user interaction, allowing an authenticated attacker to trigger memory corruption and achieve arbitrary code execution with elevated privileges.

Summary generated and translated by AI from the official description.
Integer overflow or wraparound in Windows Fast FAT Driver allows an unauthorized attacker to execute code locally.
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →