216.73.217.22

CVE-2025-1865

· Published 04/04/2025 10:15 · Modified 04/04/2025 10:15

Labels: CVE-2025-1865 2025-04-04CVE-2025-1865CWE-284a341c0d1-ebf7-493f-a84e-38cf86618674

Essential information

Published
04/04/2025 10:15
Modified
04/04/2025 10:15
Author
Creator
CVSS
8.5 HIGH (v3) 8.5 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

The kernel driver, accessible to low-privileged users, exposes a function that fails to properly validate the privileges of the calling process. This allows creating files at arbitrary locations with full user control, ultimately allowing for privilege escalation to SYSTEM.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
a341c0d1-ebf7-493f-a84e-38cf86618674
NVD
View on NVD

Affected products (CPE)

ProductCPE
vendor / kernel driver cpe:2.3:a:vendor:kernel_driver:*:*:*:*:*:*:*:*

References