CVE-2025-64298
BaseFortify
Publication date: 2025-12-02
Last updated on: 2025-12-04
Assigner: ICS-CERT
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| microsoft | sql_server_express | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-732 | The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability affects NMIS/BioDose V22.02 and earlier versions when using the embedded Microsoft SQL Server Express in networked installations. The Windows share accessed by clients exposes the directory containing the SQL Server database and configuration files. These directories have insecure paths by default, allowing unauthorized access to sensitive database and configuration files.
How can this vulnerability impact me? :
The vulnerability can lead to unauthorized access to sensitive data stored in the SQL Server database and configuration files. This can result in data confidentiality, integrity, and availability being compromised, potentially allowing attackers to read, modify, or disrupt critical information.