Headlines
Microsoft issued patches for 57 CVE-rated vulnerabilities, including six actively exploited zero-day vulnerabilities.
23 Elevation of Privilege Vulnerabilities
3 Security Feature Bypass Vulnerabilities
23 Remote Code Execution Vulnerabilities
4 Information Disclosure Vulnerabilities
1 Denial of Service Vulnerabilities
3 Spoofing Vulnerabilities
Quorum Cyber Recommendations
Patching should be completed within your regular cycles and without delay. We do not at this time recommend expedited patching.
Microsoft Release Notes
https://msrc.microsoft.com/update-guide/releaseNote/2025-Mar
Key Vulnerability Details
| Title | Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability |
| CVE | CVE-2025-24983 |
| CVSS | 7.0 |
| Reason for Concern | Reported as a Zero Day |
| Mitigations and other Factors | According to the CVSS scoring method, local access and authentication are both required for exploitation. |
| Commentary | Microsoft says this vulnerability will allow local attackers to gain SYSTEM privileges on the device after winning a race condition. |
| Threat Intelligence Comment | This flaw enables an authenticated attacker with low-level privileges to gain SYSTEM-level access, potentially leading to system compromise, arbitrary code execution, data modification, malware installation, and security bypass. Although no public proof-of-concept exists, the vulnerability is actively exploited in the wild and listed in CISA’s Known Exploited Vulnerability list. It is crucial for organisations to prioritise security updates from Microsoft, monitor for compromise indicators, and strengthen security controls to mitigate the associated risks. |
| Link | https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2025-24983 |
| Title | Windows NTFS Information Disclosure Vulnerability |
| CVE | CVE-2025-24984 |
| CVSS | 4.6 |
| Reason for Concern | Insertion of sensitive information into log file in Windows NTFS allows an unauthorised attacker to disclose information with a physical attack. |
| Mitigations and other Factors | An attacker needs physical access to the target computer to plug in a malicious USB drive. |
| Commentary | An attacker who successfully exploited this vulnerability could potentially read portions of heap memory. |
| Threat Intelligence Comment | CVE-2025-24984 is a vulnerability in the Windows NTFS logging mechanism that allows an attacker with physical access to a computer to extract sensitive heap memory data through log file manipulation. An attacker needs to plug in a malicious USB drive to exploit this vulnerability and potentially read portions of heap memory. This poses a significant risk, especially in environments with limited physical access controls, as it allows attackers to extract sensitive system information without requiring privileges or user interaction. While there is no public proof-of-concept available, the vulnerability is actively exploited in the wild and has been added to the CISA Known Exploited Vulnerability list. Organisations should ensure robust physical security measures and monitor systems for signs of compromise to mitigate the risk associated with this vulnerability. |
| Link | CVE-2025-24984 – Security Update Guide – Microsoft – Windows NTFS Information Disclosure Vulnerability |
| Title |
| ||
| CVV | CVE-2025-24985 | ||
| CVSS | 7.8 | ||
| Reason for Concern | The word Remote in the title refers to the location of the attacker. This type of exploit is sometimes referred to as Arbitrary Code Execution (ACE). The attack itself is conducted locally. This means an attacker or victim needs to execute code from the local machine to exploit the vulnerability | ||
| Mitigations and other Factors | Successful exploitation of this vulnerability requires that an attacker will need to first gain access to the restricted network before running an attack as well as multiple other conditions, such as specific application behaviour, user actions (a restart is required), manipulation of parameters passed to a function, and impersonation of an integrity level token. | ||
| Commentary | An attacker can trick a local user on a vulnerable system into mounting a specially crafted VHD that would then trigger the vulnerability. | ||
| Threat Intelligence Comment | CVE-2025-24985 is a remote code execution vulnerability caused by an integer overflow or wraparound in the Windows Fast FAT Driver. This vulnerability allows an attacker to execute code by tricking a local user into mounting a specially crafted VHD file. Despite the “remote” designation, the attack requires local execution on the vulnerable system. Exploiting this vulnerability can lead to complete system compromise with the privileges of the logged-in user, resulting in high integrity and availability impacts. While there is no public proof-of-concept available, the vulnerability is actively being exploited in the wild and has been added to the CISA Known Exploited Vulnerability list. Organisations should prioritise applying security updates, educate users on the risks of mounting untrusted VHD files. | ||
| Link | CVE-2025-24985 – Security Update Guide – Microsoft – Windows Fast FAT File System Driver Remote Code Execution Vulnerability |
| Title | Windows NTFS Information Disclosure Vulnerability |
| CVE | CVE-2025-24991 |
| CVSS | 5.5 |
| Reason for Concern | An attacker who successfully exploited this vulnerability could potentially read small portions of heap memory. |
| Mitigations and other Factors | The word Remote in the title refers to the location of the attacker. This type of exploit is sometimes referred to as Arbitrary Code Execution (ACE). The attack itself is carried out locally. This means an attacker or victim needs to execute code from the local machine to exploit the vulnerability |
| Commentary | An attacker can trick a local user on a vulnerable system into mounting a specially crafted VHD that would then trigger the vulnerability. |
| Threat Intelligence Comment | CVE-2025-24991 is an out-of-bounds read vulnerability in the Windows NTFS file system that allows local information disclosure through specially crafted VHD file interactions. An attacker can trick a local user into mounting a malicious VHD file, which then triggers the vulnerability, potentially allowing the attacker to read small portions of heap memory. This type of exploit, despite being referred to as remote, requires local code execution on the vulnerable system. Successful exploitation can expose sensitive system and application data, compromising system integrity and user privacy. While there is no public proof-of-concept available, the vulnerability is actively being exploited in the wild and has been added to the CISA Known Exploited Vulnerability list. Organisations should ensure users are cautious about mounting untrusted VHD files, apply security updates promptly, and monitor systems for signs of exploitation to mitigate the associated risks. |
| Link | CVE-2025-24991 – Security Update Guide – Microsoft – Windows NTFS Information Disclosure Vulnerability |
| Title | Windows NTFS Remote Code Execution Vulnerability |
| CVE | CVE-2025-24993 |
| CVSS | 7.8 |
| Reason for Concern | Heap-based buffer overflow in Windows NTFS allows an unauthorised attacker to execute code locally. |
| Mitigations and other Factors | The word Remote in the title refers to the location of the attacker. This type of exploit is sometimes referred to as Arbitrary Code Execution (ACE). The attack itself is carried out locally. This means an attacker or victim needs to execute code from the local machine to exploit the vulnerability |
| Commentary | An attacker can trick a local user on a vulnerable system into mounting a specially crafted VHD that would then trigger the vulnerability. |
| Threat Intelligence Comment | CVE-2025-24993 is a heap-based buffer overflow vulnerability in Windows NTFS that allows an unauthorised attacker to execute code locally. Despite the “remote” designation, the attack requires local execution on the vulnerable system. An attacker can trick a local user into mounting a specially crafted VHD file, which triggers the vulnerability. This exploit does not require special privileges but relies on user interaction. Successful exploitation can lead to high-privilege code execution on the affected system, resulting in complete system compromise. The vulnerability has significant impacts on confidentiality, integrity, and availability. While no public proof-of-concept exists, the vulnerability is actively exploited in the wild and has been added to the CISA Known Exploited Vulnerability list. Organisations should prioritise applying security updates and educate users on the risks of mounting untrusted VHD files. |
| Link | CVE-2025-24993 – Security Update Guide – Microsoft – Windows NTFS Remote Code Execution Vulnerability |
| Title | Microsoft Access Remote Code Execution Vulnerability |
| CVE | CVE-2025-26630 |
| CVSS | 7.8 |
| Reason for Concern | Use after free in Microsoft Office Access allows an unauthorised attacker to execute code locally. |
| Mitigations and other Factors | A user needs to be tricked into running malicious files. |
| Commentary | The attacker needs to convince a victim to download and open a specially crafted file from a website which leads to a local attack on their computer. In this instance, the preview pane is NOT an attack vector. |
| Threat Intelligence Comment | CVE-2025-26630 is a use-after-free vulnerability in Microsoft Office Access that allows an unauthorised attacker to execute code locally. Exploitation of this vulnerability requires tricking a user into downloading and opening a specially crafted file from a website. The preview pane is not an attack vector in this instance, meaning the file must be explicitly opened by the user. Successful exploitation can lead to arbitrary code execution with the same privileges as the current user, resulting in high impacts on system integrity and availability. This can include data manipulation, system disruption, or unauthorised access. Although there is no public proof-of-concept available the vulnerability is currently being actively exploited. Organisations should ensure that users are aware of the risks of opening files from untrusted sources, apply relevant security updates. |
| Link | https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2025-26630 |
Additional Releases
Aside from Microsoft, the following vendors have issued updates for significant vulnerabilities:
Broadcom fixed three zero-day flaws in VMware ESXi that were exploited in attacks.
Cisco fixes WebEx flaw that could expose credentials, as well as critical vulnerabilities in Cisco Small Business routers.
An unpatched Edimax IC-7100 IP camera flaw is being exploited by botnet malware to infect devices.
Google fixed an exploited zero-day flaw in an Android’s Linux kernel driver that was used to unlock devices.
Ivanti released security updates for Secure Access Client (SAC) and Neurons for MDM.
Fortinet released security updates for numerous products, including FortiManager, FortiOS, FortiAnalyzer, and FortiSandbox.
Paragon disclosed a flaw in its BioNTdrv.sys driver that was exploited by ransomware gangs in BYOVD attacks.
SAP releases security updates for multiple products.












