Full Report
Slovak cybersecurity company ESET says a newly patched zero-day vulnerability in the Windows Win32 Kernel Subsystem has been exploited in attacks since March 2023. [...]
Analysis Summary
# Vulnerability: Multiple Actively Exploited Windows Kernel Zero-Days Patched in March 2025
## CVE Details
The article references several vulnerabilities patched in March 2025, including zero-days actively exploited since 2023 and 2025. Specific CVEs mentioned are:
- CVE ID: CVE-2023-28252 (Mentioned in context of being exploited previously)
- CVE ID: CVE-2025-24984
- CVE ID: CVE-2025-24985
- CVE ID: CVE-2025-24991
- CVE ID: CVE-2025-24993
- CVE ID: CVE-2025-26633
- CVSS Score: *Not explicitly provided for the new CVEs or CVE-2023-28252 in the snippet, but context implies high severity.*
- CWE: *Not specified in the snippet for specific CVEs.*
## Affected Systems
- Products: Windows operating systems (Specifically components within the Windows Kernel, NTFS, and the Common Log File System Driver).
- Versions: Specific vulnerable versions are not listed, but all versions affected by the March 2025 Patch Tuesday updates covering these flaws should be considered vulnerable until patched.
- Configurations: Not specified, but kernel-level components are typically system-wide.
## Vulnerability Description
The primary focus is on a **Windows Kernel zero-day vulnerability** (implied to have been under active exploitation since 2023), which was patched alongside five other zero-days during the March 2025 Patch Tuesday. These vulnerabilities span several critical Windows components:
1. **CVE-2023-28252:** A **Privilege Escalation** flaw in the **Common Log File System Driver**.
2. **CVE-2025-24985:** **Remote Code Execution (RCE)** in the **Windows Fast FAT File System Driver**.
3. **CVE-2025-24993:** **Remote Code Execution (RCE)** in **Windows NTFS**.
4. **CVE-2025-24984 & CVE-2025-24991:** **Information Disclosure** vulnerabilities in **Windows NTFS**.
5. **CVE-2025-26633:** **Security Feature Bypass** vulnerability in the **Microsoft Management Console**.
## Exploitation
- Status: Explicitly identified as **Actively exploited in the wild** (Zero-Day status for all six patched vulnerabilities, including one exploited since 2023).
- Complexity: *Implied Low to Medium, given the privilege escalation and RCE capabilities and wide-scale exploitation.*
- Attack Vector: Likely **Local** for privilege escalation and RCE on host systems, consistent with core kernel/driver flaws, though initial access vectors are not detailed.
## Impact
- Confidentiality: Moderate to High (Due to Information Disclosure and RCE capabilities).
- Integrity: High (Due to Privilege Escalation and RCE).
- Availability: Potential impact depending on the nature of the exploit chain.
## Remediation
### Patches
Microsoft released patches for all six zero-days and 51 other flaws during the March 2025 Patch Tuesday.
- **Action Required:** Apply all cumulative updates released in March 2025 to secure the affected components.
### Workarounds
- No specific workarounds were detailed in the provided text. Remediation should focus on applying the vendor patches immediately.
## Detection
- **Indicators of Compromise (IOCs):** Not specified in detail, but monitoring for anomalous activity related to kernel mode operations, file system driver interactions, and unexpected privilege changes would be relevant.
- **Detection Methods and Tools:** Organizations should rely on Microsoft's security advisories and endpoint detection and response (EDR) solutions configured to monitor for exploitation attempts targeting kernel vulnerabilities.
## References
- Vendor Advisory: Microsoft March 2025 Security Update Guide (Implied, as these were part of Patch Tuesday).
- CISA Alert: CISA added all six zero-days to its Known Exploited Vulnerabilities Catalog on March 11, 2025.
- Advisory Links (Defanged):
- hxxps://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-28252
- hxxps://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2025-24984
- hxxps://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2025-24985
- hxxps://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2025-24991
- hxxps://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2025-24993
- hxxps://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2025-26633
- hxxps://www.cisa.gov/news-events/alerts/2025/03/11/cisa-adds-six-known-exploited-vulnerabilities-catalog