Vulnerability record · CVE-2025-24985 · published 11 March 2025
CVE-2025-24985: Windows Fast FAT Driver integer overflow enables local code execution
Microsoft · Windows 10 1507
The Windows Fast FAT driver contains an integer overflow that leads to a heap-based buffer overflow. A crafted FAT filesystem operation can corrupt heap memory, and because the flaw is in a core filesystem driver it affects a wide range of Windows client and server releases.
Description
Integer overflow or wraparound in Windows Fast FAT Driver allows an unauthorized attacker to execute code locally.
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityThe flaw is in a core Windows driver, allows local code execution with high confidentiality, integrity and availability impact, and is listed in CISA KEV with active exploitation reported.
What it is
The Windows Fast FAT driver contains an integer overflow that leads to a heap-based buffer overflow. A crafted FAT filesystem operation can corrupt heap memory, and because the flaw is in a core filesystem driver it affects a wide range of Windows client and server releases.
Impact
An attacker who triggers the overflow can execute code in the context of the affected driver, potentially gaining kernel-level privileges on the target host. This can lead to full system compromise.
Attack surface
The vulnerability is local (AV:L) and requires user interaction (UI:R), meaning an attacker must get a user to open or mount a crafted FAT image or otherwise cause the driver to process malicious input. No authentication is required (PR:N).
Exploitation
CISA added this CVE to the Known Exploited Vulnerabilities catalog on 2025-03-11 with a remediation due date of 2025-04-01, indicating active exploitation. EPSS gives a 30-day exploitation probability of about 3.8% (89.6th percentile), and a third-party reference is tagged as an exploit.
What to do
- Apply the Microsoft security update for CVE-2025-24985 as soon as possible, prioritizing internet-facing and multi-user systems.
- Follow CISA BOD 22-01 guidance and treat the 2025-04-01 due date as a hard deadline for remediation.
- Restrict the ability to mount or open untrusted FAT-formatted media and images on production endpoints.
- Where patching is delayed, consider disabling or limiting the Fast FAT driver on systems that do not require FAT support.
- Monitor vendor advisories for updated mitigations if the patch cannot be deployed immediately.
Detection
- Monitor for unexpected crashes or bugchecks in the Fast FAT driver (fastfat.sys) on endpoints.
- Audit process and file activity around mounting or opening FAT images and removable media, especially from untrusted sources.
- Use the third-party detection script referenced in the advisory to hunt for indicators of the integer overflow condition.
- Correlate local privilege escalation attempts or unusual kernel-mode activity with FAT filesystem operations.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2025-24985 to the Known Exploited Vulnerabilities catalog on 11 March 2025 as "Microsoft Windows Fast FAT File System Driver Integer Overflow Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 1 April 2025.
Affected products
15 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-24985 | PatchVendor Advisory |
| https://www.vicarius.io/vsociety/posts/cve-2025-24985-integer-overflow-vulnerability-in-microsoft-windows-fast-fat-drive | ExploitThird Party Advisory |
| https://www.vicarius.io/vsociety/posts/cve-2025-24985-integer-overflow-vulnerability-in-microsoft-windows-fast-fat-drive | MitigationThird Party Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-24985 | US Government Resource |
Track CVE-2025-24985 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2025-24985), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.