CVE-2025-58097
Unknown Unknown - Not Provided
BaseFortify

Publication date: 2025-11-21

Last updated on: 2025-12-05

Assigner: JPCERT/CC

Description
The installation directory of LogStare Collector is configured with incorrect access permissions. A non-administrative user may manipulate files within the installation directory and execute arbitrary code with the administrative privilege.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2025-11-21
Last Modified
2025-12-05
Generated
2026-06-16
AI Q&A
2025-11-21
EPSS Evaluated
2026-06-15
NVD
EUVD
Affected Vendors & Products
Showing 3 associated CPEs
Vendor Product Version / Range
secuavail logstare_collector to 2.4.2 (exc)
linux linux_kernel *
microsoft windows *
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-276 During installation, installed file permissions are set to allow anyone to modify those files.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

This vulnerability occurs because the installation directory of LogStare Collector has incorrect access permissions. This misconfiguration allows a non-administrative user to manipulate files within the installation directory and potentially execute arbitrary code with administrative privileges.

Impact Analysis

The vulnerability can allow a non-administrative user to gain administrative privileges by manipulating files in the installation directory. This could lead to unauthorized code execution with high-level privileges, potentially compromising the security and integrity of the affected system.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-58097. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart