CVE-2025-22894CWE-422
Unprotected Windows messaging channel ('Shatter') issue exists in Defense Platform Home Edition Ver.3.9.51.x and earlier
Medium · published February 6, 2025
What it is
Unprotected Windows messaging channel ('Shatter') issue exists in Defense Platform Home Edition Ver.3.9.51.x and earlier. If an attacker sends a specially crafted message to the specific process of the Windows system where the product is running, arbitrary files in the system may be altered. As a result, an arbitrary DLL may be executed with SYSTEM privilege.
The record
Technical detail
- CVSS v3.0
- 6.5 · MEDIUM
- Vector
- CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N
- CVSS v4.0
- Not supplied
- EPSS
- 0.00142 · 3.8th percentile
- Weakness
- CWE-422 · Unprotected Windows Messaging Channel ('Shatter')
- Published
- 2025-02-06T07:05Z
EPSS history
Timeline