CVE-2025-14614
Insecure Temporary File Vulnerability in Altera Quartus Prime Installers
Publication date: 2026-01-07
Last updated on: 2026-01-07
Assigner: Altera
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| altera | quartus_prime_standard | From 23.1 (inc) to 24.1 (inc) |
| altera | quartus_prime_lite | From 23.1 (inc) to 24.1 (inc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-377 | Creating and using insecure temporary files can leave application and system data vulnerable to attack. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is an Insecure Temporary File issue in the Altera Quartus Prime Standard and Lite Installers on Windows. It allows an attacker to predict temporary file names used by the installer, which can lead to security risks such as unauthorized access or modification of these temporary files during installation.
How can this vulnerability impact me? :
The vulnerability can impact you by allowing attackers with local access to exploit predictable temporary file names, potentially leading to unauthorized information disclosure, modification, or disruption of the installation process. This could compromise the integrity and confidentiality of the software installation.