← Voltar para CVEs
CVE-2025-63945
HIGH7.4
Descricao
A privilege escalation (PE) vulnerability in the Tencent iOA app thru 210.9.28693.621001 on Windows devices enables a local user to execute programs with elevated privileges. However, execution requires that the local user is able to successfully exploit a race condition.
Detalhes CVE
Pontuacao CVSS v3.17.4
SeveridadeHIGH
Vetor CVSSCVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Vetor de ataqueLOCAL
ComplexidadeHIGH
Privilegios necessariosNONE
Interacao do usuarioNONE
Publicado2/23/2026
Ultima modificacao2/26/2026
Fontenvd
Avistamentos honeypot0
Produtos afetados
tencent:ioa
Fraquezas (CWE)
CWE-59
Referencias
https://github.com/alexlee820/CVE-2025-63945-Tencent-iOA-EoP(cve@mitre.org)
https://github.com/alexlee820/Tencent-iOA-EoP(cve@mitre.org)
Correlacoes IOC
Sem correlacoes registradas
This product uses data from the NVD API but is not endorsed or certified by the NVD.