CVE-2025-64701CWE-268

QND Premium/Advance/Standard Ver.11.0.9i and prior contains a privilege escalation vulnerability, which may allow a user who can log in to a Windows system…

High · published December 11, 2025

CVSS v4.0
8.5
EPSS
0%
Percentile
1.9
In the wild
Unconfirmed
What it is

⚡ A logged-in user could easily escalate their privileges to admin status in QND Premium/Advance/Standard versions up to 11.0.9i — it’s like finding an unguarded back door in your home! 🔥 Think of it as a guest who checks into a hotel but finds a way to access the manager's suite — all because the door was carelessly left unlocked! This vulnerability allows unauthorized access to sensitive information and system controls. An attacker could read, modify, or delete sensitive data, and even execute arbitrary commands! This poses a significant risk to the integrity of your system, potentially resulting in data breaches or unauthorized system changes. Losing control over your system could be absolutely devastating!

Put simply

Think of it as a guest who checks into a hotel but finds a way to access the manager's suite — all because the door was carelessly left unlocked! This vulnerability allows unauthorized access to sensitive information and system controls. This privilege escalation vulnerability allows an authenticated user to gain administrator access by exploiting flaws in the application’s permission checks. Once logged in, they can navigate to elevated functions that should be restricted.

What to do

An attacker could read, modify, or delete sensitive data, and even execute arbitrary commands! This poses a significant risk to the integrity of your system, potentially resulting in data breaches or unauthorized system changes. Losing control over your system could be absolutely devastating! Immediately update to version 11.0.9j or higher to patch this vulnerability. Review your user access policies and audit permissions to ensure that only authorized users have elevated privileges. Regularly check for updates to maintain system security. You've got this! With just a few quick steps, you can secure your system and keep your data safe! 🛡️

The record
Technical detail
CVSS v4.0
8.5 · HIGH
Vector
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
EPSS
0.00119 · 1.9th percentile
Weakness
CWE-268 · Privilege Chaining
Published
2025-12-11T08:13Z
EPSS history
Timeline
  • 11 DEC 08:13Z
    QND Premium/Advance/Standard Ver.11.0.9i and prior contains a privilege escalation vulnerability, which may allow a user who can log in to a Windows system…
    cvelistv5