CVE-2025-21180 — Windows exFAT File System Remote Code Execution Vulnerability
Executive Summary
Heap-based buffer overflow in Windows exFAT File System allows an unauthorized attacker to execute code locally.
Overview
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
EPSS Score
Affected Products
| Product | KB Article | Severity | Impact | Restart Required |
|---|---|---|---|---|
| Windows 10 for 32-bit Systems | 5053618 (Security Update) |
Important | Remote Code Execution | Yes |
| Windows 10 for x64-based Systems | 5053618 (Security Update) |
Important | Remote Code Execution | Yes |
| Windows 10 Version 1607 for 32-bit Systems | 5053594 (Security Update) |
Important | Remote Code Execution | Yes |
| Windows 10 Version 1607 for x64-based Systems | 5053594 (Security Update) |
Important | Remote Code Execution | Yes |
| Windows 10 Version 1809 for 32-bit Systems | 5053596 (Security Update) |
Important | Remote Code Execution | Yes |
| Windows 10 Version 1809 for x64-based Systems | 5053596 (Security Update) |
Important | Remote Code Execution | Yes |
| Windows 10 Version 21H2 for 32-bit Systems | 5053606 (Security Update) |
Important | Remote Code Execution | Yes |
| Windows 10 Version 21H2 for ARM64-based Systems | 5053606 (Security Update) |
Important | Remote Code Execution | Yes |
| Windows 10 Version 21H2 for x64-based Systems | 5053606 (Security Update) |
Important | Remote Code Execution | Yes |
| Windows 10 Version 22H2 for 32-bit Systems | 5053606 (Security Update) |
Important | Remote Code Execution | Yes |
| Windows 10 Version 22H2 for ARM64-based Systems | 5053606 (Security Update) |
Important | Remote Code Execution | Yes |
| Windows 10 Version 22H2 for x64-based Systems | 5053606 (Security Update) |
Important | Remote Code Execution | Yes |
| Windows 11 Version 22H2 for ARM64-based Systems | 5053602 (Security Update) |
Important | Remote Code Execution | Yes |
| Windows 11 Version 22H2 for x64-based Systems | 5053602 (Security Update) |
Important | Remote Code Execution | Yes |
| Windows 11 Version 23H2 for ARM64-based Systems | 5053602 (Security Update) |
Important | Remote Code Execution | Yes |
| Windows 11 Version 23H2 for x64-based Systems | 5053602 (Security Update) |
Important | Remote Code Execution | Yes |
| Windows 11 Version 24H2 for ARM64-based Systems 5053598 (Security Update) 5053636 (SecurityHotpatchUpdate) Important Remote Code Execution 5051987 5052105 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 10.0.26100.3476 10.0.26100.3403 Yes None Windows 11 Version 24H2 for x64-based Systems 5053598 (Security Update) 5053636 (SecurityHotpatchUpdate) Important Remote Code Execution 5051987 5052105 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 10.0.26100.3476 10.0.26100.3403 Yes None Windows Server 2008 for 32-bit Systems Service Pack 2 5053888 (Monthly Rollup) 5053995 (Security Only) Important Remote Code Execution 5052038 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.0.6003.23168 Yes None Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation) 5053888 (Monthly Rollup) 5053995 (Security Only) Important Remote Code Execution 5052038 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.0.6003.23168 Yes None Windows Server 2008 for x64-based Systems Service Pack 2 5053888 (Monthly Rollup) 5053995 (Security Only) Important Remote Code Execution 5052038 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.0.6003.23168 Yes None Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation) 5053888 (Monthly Rollup) 5053995 (Security Only) Important Remote Code Execution 5052038 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.0.6003.23168 Yes None Windows Server 2008 R2 for x64-based Systems Service Pack 1 5053620 (Monthly Rollup) 5053627 (Security Only) Important Remote Code Execution 5052016 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.1.7601.27618 Yes None Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation) 5053620 (Monthly Rollup) 5053627 (Security Only) Important Remote Code Execution 5052016 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 6.1.7601.27618 Yes None Windows Server 2012 | 5053886 (Monthly Rollup) |
Important | Remote Code Execution | Yes |
| Windows Server 2012 (Server Core installation) | 5053886 (Monthly Rollup) |
Important | Remote Code Execution | Yes |
| Windows Server 2012 R2 | 5053887 (Monthly Rollup) |
Important | Remote Code Execution | Yes |
| Windows Server 2012 R2 (Server Core installation) | 5053887 (Monthly Rollup) |
Important | Remote Code Execution | Yes |
| Windows Server 2016 | 5053594 (Security Update) |
Important | Remote Code Execution | Yes |
| Windows Server 2016 (Server Core installation) | 5053594 (Security Update) |
Important | Remote Code Execution | Yes |
| Windows Server 2019 | 5053596 (Security Update) |
Important | Remote Code Execution | Yes |
| Windows Server 2019 (Server Core installation) | 5053596 (Security Update) |
Important | Remote Code Execution | Yes |
| Windows Server 2022 5053603 (Security Update) 5053638 (SecurityHotpatchUpdate) Important Remote Code Execution 5051979 5052106 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 10.0.20348.3328 10.0.20348.3270 Yes None Windows Server 2022 (Server Core installation) 5053603 (Security Update) 5053638 (SecurityHotpatchUpdate) Important Remote Code Execution 5051979 5052106 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 10.0.20348.3328 10.0.20348.3270 Yes None Windows Server 2022, 23H2 Edition (Server Core installation) | 5053599 (Security Update) |
Important | Remote Code Execution | Yes |
Patches
| Article | Type | Restart |
|---|---|---|
5053618 |
Security Update | Yes |
5053594 |
Security Update | Yes |
5053596 |
Security Update | Yes |
5053606 |
Security Update | Yes |
5053602 |
Security Update | Yes |
5053886 |
Monthly Rollup | Yes |
5053887 |
Monthly Rollup | Yes |
5053599 |
Security Update | Yes |
Patch Diff
Integer overflow leading to a heap-based buffer overflow (CWE-122) in the Windows exFAT file-system driver exfat.sys, mount-time arbitrary code execution (Important, RCE, AV:L, UI:R, CVSS 7.8, Exploitation More Likely). When an exFAT volume is mounted, FppSetupAllocationSupport derives the allocation-bitmap support parameters from untrusted on-disk metadata and sizes the in-memory allocation structures. PRE: it took a 32-bit count/length from the volume (param_2 + 0x138) and rounded it up by adding 0xffff WITHOUT an overflow check, so a crafted volume supplying a value near 0xFFFFFFFF wrapped the 32-bit addition to a small number, producing an undersized heap allocation that was then overrun when the structures were populated - a heap overflow reachable at mount time. Because exFAT parses the volume when it is mounted, an attacker who tricks a local user into mounting a malicious VHD (AV:L, UI:R) can trigger the overflow for kernel code execution. Diff of exfat.sys 10.0.26100.2454 -> .3470 (Mar 11 2025, KB5053598) confirms the fix: FppSetupAllocationSupport gains an overflow guard gated behind CFR flag Feature_930095419 - if (uVar7 + 0xffff < uVar7) it sets STATUS_FILE_CORRUPT_ERROR (0xc0000102) and calls ExRaiseStatus() to abort the mount before the undersized allocation is made. (Wide .2454->.3470 span that also linked in CFR feature-usage instrumentation; the security-relevant change is the overflow guard.)
| Function | Address | Change | Note |
|---|---|---|---|
FppSetupAllocationSupport |
code change |
code (adds +0xffff rounding overflow guard, CFR-gated) | Pre: allocation-support size computed as volume_count + 0xffff in 32-bit with no overflow check -> near-UINT_MAX count wraps to a tiny size -> undersized heap allocation -> overflow. Post (Feature_930095419): if (uVar7 + 0xffff < uVar7) set STATUS_FILE_CORRUPT_ERROR (0xc0000102) and ExRaiseStatus() to abort the mount. |
DriverEntry |
code change |
code (CFR feature registration linked in) | DriverEntry and the RtlRegister/RecordFeatureUsage imports were added when this build introduced Feature_930095419 CFR gating to exfat; not the vulnerable code itself. |
Feature_930095419 |
gate |
added (CFR gate) | CFR flag gating the overflow guard in FppSetupAllocationSupport; the original unchecked rounding still ships when the flag is disabled. |
Attack Path
A crafted exFAT volume overflows the allocation-support size rounding, undersizing a heap buffer that is then overrun at mount
Derived from the patch delta: the checks added by the vendor identify which fields crossed a trust boundary unvalidated. Reachability and privilege are taken from the call chain in the RCA report.