CVE-2025-22894CWE-422

Unprotected Windows messaging channel ('Shatter') issue exists in Defense Platform Home Edition Ver.3.9.51.x and earlier

Medium · published February 6, 2025

CVSS v3.0
6.5
EPSS
0%
Percentile
3.8
In the wild
Unconfirmed
What it is

Unprotected Windows messaging channel ('Shatter') issue exists in Defense Platform Home Edition Ver.3.9.51.x and earlier. If an attacker sends a specially crafted message to the specific process of the Windows system where the product is running, arbitrary files in the system may be altered. As a result, an arbitrary DLL may be executed with SYSTEM privilege.

The record
Technical detail
CVSS v3.0
6.5 · MEDIUM
Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N
CVSS v4.0
Not supplied
EPSS
0.00142 · 3.8th percentile
Weakness
CWE-422 · Unprotected Windows Messaging Channel ('Shatter')
Published
2025-02-06T07:05Z
EPSS history
Timeline
  • 06 FEB 07:05Z
    Unprotected Windows messaging channel ('Shatter') issue exists in Defense Platform Home Edition Ver.3.9.51.x and earlier
    cvelistv5