CVE-2025-20094CWE-422

Unprotected Windows messaging channel ('Shatter') issue exists in Defense Platform Home Edition Ver.3.9.51.x and earlier

High · published February 6, 2025

CVSS v3.0
8.8
EPSS
0%
Percentile
4.7
In the wild
Unconfirmed
What it is

Unprotected Windows messaging channel ('Shatter') issue exists in Defense Platform Home Edition Ver.3.9.51.x and earlier. If an attacker sends a specially crafted message to the specific process of the Windows system where the product is running, arbitrary code may be executed with SYSTEM privilege.

The record
Technical detail
CVSS v3.0
8.8 · HIGH
Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CVSS v4.0
Not supplied
EPSS
0.00152 · 4.7th percentile
Weakness
CWE-422 · Unprotected Windows Messaging Channel ('Shatter')
Published
2025-02-06T07:05Z
EPSS history
Timeline
  • 06 FEB 07:05Z
    Unprotected Windows messaging channel ('Shatter') issue exists in Defense Platform Home Edition Ver.3.9.51.x and earlier
    cvelistv5