CVE-2025-3773
BaseFortify
Publication date: 2025-06-26
Last updated on: 2026-02-11
Assigner: Trellix
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| trellix | system_information_reporter | to 1.0.3 (inc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-530 | A backup file is stored in a directory or archive that is made accessible to unauthorized actors. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is a sensitive information exposure issue in System Information Reporter (SIR) version 1.0.3 and earlier. It allows an authenticated local user who does not have administrative privileges to access and extract sensitive information stored in a registry backup folder.
How can this vulnerability impact me? :
The vulnerability could lead to unauthorized disclosure of sensitive information by allowing a non-admin local user to access registry backup data that should be protected. This exposure could potentially be used to gather information that might aid in further attacks or compromise system security.