Description
fastfat.sys (aka the FASTFAT driver) in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Vista SP2, and Server 2008 SP2 does not properly allocate memory, which allows physically proximate attackers to execute arbitrary code or cause a denial of service (reserved-memory write) by connecting a crafted USB device, aka "Microsoft Windows Disk Partition Driver Elevation of Privilege Vulnerability."
References (4)
Core 4
Core References
Vendor Advisory x_refsource_confirm
http://blogs.technet.com/b/srd/archive/2014/10/14/accessing-risk-for-the-october-2014-security-updates.aspx
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/70343
Vendor Advisory vendor-advisory
x_refsource_ms
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2014/ms14-063
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/60975
Scores
EPSS
0.0288
EPSS Percentile
85.5%
Details
CWE
CWE-399
Status
published
Products (3)
microsoft/windows_server_2003
microsoft/windows_server_2008
microsoft/windows_vista
Published
Oct 15, 2014
Tracked Since
Feb 18, 2026