Release Notes
v1.0
Search this version
Release Notes
Release Notes
Security SDK
AppRemover
V3V4 Adapter
VModSource
Title
Message
Create new category
What is the title of your new category?
Edit page index title
What is the title of the page index?
Edit category
What is the new title of your category?
Edit link
What is the new title and URL of your link?
CVE-2025-0131
Copy Markdown
Open in ChatGPT
Open in Claude
Description
An incorrect privilege management vulnerability in the OPSWAT MetaDefender Endpoint Security SDK on Windows devices allows a locally authenticated non-administrative Windows user to escalate their privileges to NT AUTHORITY\SYSTEM. However, execution requires that the local user also successfully exploits a race condition, which makes this vulnerability difficult to exploit.
References
https://www.opswat.com/products/metadefender/endpoint-security-sdk
Severity
CVSS-BT: 4.0
CVSS-B: 7.1
Vector: CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:H/SI:H/SA:H/E:U/AU:N/R:U/V:D/U:Amber
Weakness Enumeration
CWE-266: Incorrect Privilege Assignment
CAPEC-233 Privilege Escalation
Known Software Configurations
MetaDefender Endpoint Security SDK version up-to (by excluding) 4.3.4451.0 (published January 21st, 2025).
Discoverer
Type to search, ESC to discard
Type to search, ESC to discard
Type to search, ESC to discard
Last updated by Morrissey on May 15, 2025
Was this page helpful?
Discard Changes
Do you want to discard your current changes and overwrite with the template?
Archive Synced Block
Message
Create new Template
What is this template's title?
Delete Template
Message
