216.73.217.22

CVE-2025-61161

· Published 29/10/2025 14:15 · Modified 29/10/2025 15:15

Labels: CVE-2025-61161 2025-10-29CVE-2025-61161CWE-427[email protected]

Essential information

Published
29/10/2025 14:15
Modified
29/10/2025 15:15
Author
Creator
CVSS
8.4 HIGH (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS metrics

Description

DLL hijacking vulnerability in Evope Collector 1.1.6.9.0 and related components load the wtsapi32.dll library from an uncontrolled search path (C:\ProgramData\Evope). This allows local unprivileged attackers to execute arbitrary code or escalate privileges to SYSTEM by placing a crafted DLL in that location. The vulnerable component is Evope.Service.exe, which runs with SYSTEM privileges and automatically loads the DLL on startup or reboot.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
evope / collector cpe:2.3:a:evope:collector:1.1.6.9.0:*:*:*:*:*:*:*
evope / evope.service cpe:2.3:a:evope:evope.service:*:*:*:*:*:*:*:*

References