CVE-2025-65001

8.2

Fujitsu · fbiosdrv.sys

The Fujitsu fbiosdrv.sys driver contains an out-of-bounds write vulnerability that could allow a privileged attacker to compromise system confidentiality, integrity, and availability.

Executive summary

A high-severity out-of-bounds write vulnerability in the Fujitsu fbiosdrv.sys driver permits privileged attackers to achieve full system compromise.

Vulnerability

This vulnerability, identified as an out-of-bounds write (CWE-787), occurs within the kernel-level driver and requires an attacker to possess high privileges on the local system to trigger the flaw.

Business impact

The vulnerability carries a CVSS score of 8.2, reflecting a significant risk to organizational assets. Because this flaw allows for potential code execution or system-wide disruption, it could lead to full loss of control over affected workstations or servers, unauthorized data access, and prolonged operational downtime.

Remediation

Immediate Action: Update the Fujitsu fbiosdrv.sys driver to version 2.5.0.0 or later as provided in the official vendor security notice.

Proactive Monitoring: Monitor system logs for unusual kernel-mode activity or unexpected driver crashes that may indicate an attempt to exploit memory corruption vulnerabilities.

Compensating Controls: Ensure that local administrative privileges are strictly limited to necessary personnel to prevent unauthorized actors from reaching the level of access required to trigger this driver-level exploit.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the critical nature of kernel-level driver vulnerabilities, organizations should prioritize the deployment of the vendor-provided security update. Restricting administrative access on endpoints remains a fundamental security control that effectively neutralizes the primary attack vector for this vulnerability.

More Fujitsu CVEs

Sources