CVE-2025-65001
8.2Fujitsu · fbiosdrv.sys
The Fujitsu fbiosdrv.sys driver contains an out-of-bounds write vulnerability that could allow a privileged attacker to compromise system confidentiality, integrity, and availability.
Executive summary
A high-severity out-of-bounds write vulnerability in the Fujitsu fbiosdrv.sys driver permits privileged attackers to achieve full system compromise.
Vulnerability
This vulnerability, identified as an out-of-bounds write (CWE-787), occurs within the kernel-level driver and requires an attacker to possess high privileges on the local system to trigger the flaw.
Business impact
The vulnerability carries a CVSS score of 8.2, reflecting a significant risk to organizational assets. Because this flaw allows for potential code execution or system-wide disruption, it could lead to full loss of control over affected workstations or servers, unauthorized data access, and prolonged operational downtime.
Remediation
Immediate Action: Update the Fujitsu fbiosdrv.sys driver to version 2.5.0.0 or later as provided in the official vendor security notice.
Proactive Monitoring: Monitor system logs for unusual kernel-mode activity or unexpected driver crashes that may indicate an attempt to exploit memory corruption vulnerabilities.
Compensating Controls: Ensure that local administrative privileges are strictly limited to necessary personnel to prevent unauthorized actors from reaching the level of access required to trigger this driver-level exploit.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Given the critical nature of kernel-level driver vulnerabilities, organizations should prioritize the deployment of the vendor-provided security update. Restricting administrative access on endpoints remains a fundamental security control that effectively neutralizes the primary attack vector for this vulnerability.