CVE-2025-30075
Unknown Unknown - Not Provided
BaseFortify

Publication date: 2025-09-16

Last updated on: 2025-09-17

Assigner: MITRE

Description
In Alludo MindManager before 25.0.208 on Windows, attackers could potentially execute code as other local users on the same machine if they could write DLL files to directories within victims' DLL search paths.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2025-09-16
Last Modified
2025-09-17
Generated
2026-05-07
AI Q&A
2025-09-16
EPSS Evaluated
2026-05-05
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
alludo mindmanager *
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-673 The product does not prevent the definition of control spheres from external actors.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

This vulnerability is a DLL Hijacking issue in Alludo MindManager on Windows versions before 25.0.208. It allows an attacker who can write DLL files to directories in the victim's DLL search path to execute arbitrary code with the privileges of other local users on the same machine. Essentially, if an attacker can place malicious DLL files in certain folders, they can trick the software into running their code. [1]


How can this vulnerability impact me? :

The vulnerability can allow an attacker with local access to execute malicious code under the context of other local users on the same machine. This could lead to unauthorized actions being performed with the privileges of those users, potentially compromising the system or data accessible to them. [1]


What immediate steps should I take to mitigate this vulnerability?

To mitigate this vulnerability, update MindManager on Windows to version 25.0.208 or later. Additionally, restrict write permissions to directories within the DLL search paths to prevent unauthorized DLL file creation or modification by local users. [1]


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart