Microsoft says that this remote code execution vulnerability is caused by an integer overflow or wraparound in Windows Fast FAT Driver that, when exploited, allows an attacker to execute code. Microsoft says that this remote code execution vulnerability is caused by a heap-based buffer overflow bug in Windows NTFS that allows an attacker to execute code. While Microsoft has not shared any details about this flaw, based on its description, it may involve a bug that allows malicious Microsoft Management Console (.msc) files to bypass Windows security features and execute code. Microsoft says that this flaw can be exploited by attackers who have physical access to the device and insert a malicious USB drive. Microsoft says this remote code execution flaw is caused by a use after free memory bug in Microsoft Office Access. Microsoft says that attackers can exploit this flaw to read small portions heap memory and steal information. Today is Microsoft's March 2025 Patch Tuesday, which includes security updates for 57 flaws, including six actively exploited zero-day vulnerabilities. "In an email or instant message attack scenario, the attacker could send the targeted user a specially crafted file that is designed to exploit the vulnerability," explains Microsoft. Microsoft says this vulnerability will allow local attackers to gain SYSTEM privileges on the device after winning a race condition. "An attacker can trick a local user on a vulnerable system into mounting a specially crafted VHD that would then trigger the vulnerability," explains Microsoft. Microsoft classifies a zero-day flaw as publicly disclosed or actively exploited while no official fix is available. Microsoft says Aliakbar Zahravi from Trend Micro discovered this flaw. While Microsoft has not shared details about how it was exploited but malicious VHD images were previously distributed in phishing attacks and through pirated software sites. Microsoft has not shared how the flaw was exploited in attacks. Microsoft says that this vulnerability was disclosed anonymously. Microsoft says that this vulnerability was disclosed anonymously. Microsoft says that this vulnerability was disclosed anonymously. Microsoft says that this vulnerability was disclosed anonymously.
This Cyber News was published on www.bleepingcomputer.com. Publication date: Tue, 11 Mar 2025 17:50:07 +0000