CISA's list that day
11 March 2025
On CISA added 6 vulnerabilities to its list of exploited vulnerabilities, in Microsoft Windows. US federal agencies must fix them by .
Added that day
| Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|
| CVE-2025-26633Management Console (MMC) Improper Neutralization | Microsoft Windows | Patch this weekRansomware use | 0.30 | ||
| CVE-2025-24985Fast FAT File System Driver Integer Overflow | Microsoft Windows | Patch soon | 0.04 | ||
| CVE-2025-24993NTFS Heap-Based Buffer Overflow | Microsoft Windows | Patch soon | 0.02 | ||
| CVE-2025-24984NTFS Information Disclosure | Microsoft Windows | Patch soon | 0.02 | ||
| CVE-2025-24991NTFS Out-Of-Bounds Read | Microsoft Windows | Patch soon | 0.02 | ||
| CVE-2025-24983Win32k Use-After-Free | Microsoft Windows | Patch soon | 0.01 |