CyberzSOC

Publication detail
← Back to advisories & guidance

Secure by Design Alert: Eliminating Buffer Overflow Vulnerabilities ↗ source

February 12, 2025 FBI Alert
Co-sealed by: CISA, FBI, NSA

Summary

The Secure by Design initiative seeks to foster a cultural shift across the technology industry, normalizing the development of the Secure by Design Pledge, and stay informed on the latest Secure by Design Alerts. Buffer overflow vulnerabilities are a prevalent type of memory The software development community has safety software design defect that regularly lead to system compromise. The Cybersecurity and Infrastructure Security Agency twenty years of extensive knowledge and (CISA) and Federal Bureau of Investigation (FBI) recognize that effective solutions for buffer overflows— memory safety vulnerabilities encompass a wide range of issues— however, many software manufacturers many of which require significant time and effort to properly continue to expose customers to resolve. While all types of memory safety vulnerabilities can be prevented by using memory safe languages during development, products with these vulnerabilities. other mitigations may only address certain types of memory safety vulnerabilities. Regardless, buffer overflow vulnerabilities are a well understood subset of memory safety vulnerability and can be addressed by using memory safe languages and other proven techniques listed in this Alert.

News Coverage

No coverage found in monitored research blogs or news feeds.

CVEs Referenced in This Publication

CVECVSSAffected
CVE-2024-38812 9.8 Critical VMware vCenter Server VMware vCenter Server contains a heap-based buffer overflow vulnerability in the implementation of the DCERPC protocol. This vulnerability could allo…
CVE-2025-0282 9.0 Critical Ivanti Connect Secure, Policy Secure, and ZTA Gateways Ivanti Connect Secure, Policy Secure, and ZTA Gateways contain a stack-based buffer overflow which can lead to unauthenticated remote code execution.
CVE-2022-0185 8.4 High Linux Kernel Linux kernel contains a heap-based buffer overflow vulnerability in the legacy_parse_param function in the Filesystem Context functionality. This all…
CVE-2023-6549 8.2 High Citrix NetScaler ADC and NetScaler Gateway Citrix NetScaler ADC and NetScaler Gateway contain a buffer overflow vulnerability that allows for a denial-of-service when configured as a Gateway (…
CVE-2024-49138 7.8 High Microsoft Windows Microsoft Windows Common Log File System (CLFS) driver contains a heap-based buffer overflow vulnerability that allows a local attacker to escalate p…
CVE-2025-21333 7.8 High Microsoft Windows Microsoft Windows Hyper-V NT Kernel Integration VSP contains a heap-based buffer overflow vulnerability that allows a local attacker to gain SYSTEM p…

Extracted from the publication text. Each CVE links to its tracked detail page.

Vendors Named in This Publication

Each vendor links to its Known Exploited Vulnerabilities catalog page. Only vendors that appear in the KEV catalog are listed, either because the publication cites one of their KEV entries or because it names them directly.