CVE-2025-24845

Published Feb 6, 2025

Last updated 17 days ago

Overview

Description
Improper neutralization of argument delimiters in a command ('Argument Injection') issue exists in Defense Platform Home Edition Ver.3.9.51.x and earlier. If an attacker provides specially crafted data to the specific process of the Windows system where the product is running, the system may cause a Blue Screen of Death (BSOD), and as a result, cause a denial-of-service (DoS) condition.
Source
vultures@jpcert.or.jp
NVD status
Received

Risk scores

CVSS 3.0

Type
Secondary
Base score
6.3
Impact score
4
Exploitability score
1.8
Vector string
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:C/C:N/I:N/A:H
Severity
MEDIUM

Weaknesses

vultures@jpcert.or.jp
CWE-88

Social media

Hype score
Not currently trending