CVE-2025-53947
Awaiting Analysis
Awaiting Analysis - Queue
BaseFortify
Publication date: 2025-09-18
Last updated on: 2025-09-19
Assigner: ICS-CERT
Description
Description
A local attacker with low privileges on the Windows system where the
software is installed can exploit this vulnerability to corrupt
sensitive data. A data folder is created with very weak privileges,
allowing any user logged into the Windows system to modify its content.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
Currently, no data is known.
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-276 | During installation, installed file permissions are set to allow anyone to modify those files. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability occurs because a data folder is created on the Windows system with very weak permissions, allowing any user with low privileges to modify its contents. A local attacker with low privileges can exploit this to corrupt sensitive data stored in that folder.
How can this vulnerability impact me? :
The vulnerability can lead to corruption of sensitive data by unauthorized users who have low privileges on the system. This could result in data integrity issues and potential disruption of normal operations.
Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70