← Voltar para CVEs
CVE-2025-10941
HIGH7.8
Descricao
A vulnerability was determined in Topaz SERVCore Teller 2.14.0-RC2/2.14.1. Affected by this issue is some unknown functionality of the file SERVCoreTeller_2.0.40D.msi of the component Installer. Executing manipulation can lead to permission issues. The attack needs to be launched locally. You should upgrade the affected component. The vendor explains, that "this vulnerability was detected at the beginning of 2025, it was remediated because the latest published version of the installer no longer uses "nssm," which is responsible for this vulnerability".
Detalhes CVE
Pontuacao CVSS v3.17.8
SeveridadeHIGH
Vetor CVSSCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Vetor de ataqueLOCAL
ComplexidadeLOW
Privilegios necessariosLOW
Interacao do usuarioNONE
Publicado9/25/2025
Ultima modificacao9/30/2025
Fontenvd
Avistamentos honeypot0
Fraquezas (CWE)
CWE-266CWE-275
Referencias
https://vuldb.com/?ctiid.325811(cna@vuldb.com)
https://vuldb.com/?id.325811(cna@vuldb.com)
https://vuldb.com/?submit.651434(cna@vuldb.com)
Correlacoes IOC
Sem correlacoes registradas
This product uses data from the NVD API but is not endorsed or certified by the NVD.