CyberzSOC

Publication detail
← Back to advisories & guidance

Microsoft Releases March 2025 Security Updates ↗ source

March 12, 2025 JPCERT/CC Alert

Summary

Remote attackers leveraging these vulnerabilities may be able to execute arbitrary code. According to Microsoft, among the vulnerabilities, the following vulnerabilities have been confirmed to be exploited in the wild. Please consider applying the security update programs by referring to the information provided by Microsoft. Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability Windows NTFS Information Disclosure Vulnerability Windows Fast FAT File System Driver Remote Code Execution Vulnerability Windows NTFS Information Disclosure Vulnerability Windows NTFS Remote Code Execution Vulnerability Microsoft Management Console Security Feature Bypass Vulnerability Please apply the security update programs through Microsoft Update, Windows Update, etc. If you have any information regarding this alert, please contact JPCERT/CC.

News Coverage

No coverage found in monitored research blogs or news feeds.

CVEs Referenced in This Publication

CVECVSSAffected
CVE-2025-24985 7.8 High Microsoft Windows Microsoft Windows Fast FAT File System Driver contains an integer overflow or wraparound vulnerability that allows an unauthorized attacker to execut…
CVE-2025-24993 7.8 High Microsoft Windows Microsoft Windows New Technology File System (NTFS) contains a heap-based buffer overflow vulnerability that allows an unauthorized attacker to execu…
CVE-2025-24983 7.0 High Microsoft Windows Microsoft Windows Win32 Kernel Subsystem contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally.
CVE-2025-26633 7.0 High Microsoft Windows Microsoft Windows Management Console (MMC) contains an improper neutralization vulnerability that allows an unauthorized attacker to bypass a securit…
CVE-2025-24991 5.5 Medium Microsoft Windows Microsoft Windows New Technology File System (NTFS) contains an out-of-bounds read vulnerability that allows an authorized attacker to disclose infor…
CVE-2025-24984 4.6 Medium Microsoft Windows Microsoft Windows New Technology File System (NTFS) contains an insertion of sensitive Information into log file vulnerability that allows an unautho…

Extracted from the publication text. Each CVE links to its tracked detail page.

Vendors Named in This Publication

Each vendor links to its Known Exploited Vulnerabilities catalog page. Only vendors that appear in the KEV catalog are listed, either because the publication cites one of their KEV entries or because it names them directly.