CVE-2025-24845
Last modified
CVE-2025-24845 is a medium-severity vulnerability rated 5.5/10 on the CVSS scale. Improper neutralization of argument delimiters in a command ('Argument Injection') issue exists in Defense Platform Home Edition Ver.3.9.51.x and earlier. If an attacker provides specially crafted data to the specific process of the Windows system where the product is running, the system may cause a Blue Screen of Death (BSOD), and as a result, cause a denial-of-service (DoS) condition.. EPSS estimates a 0.18% chance of exploitation in the next 30 days.
Description
Improper neutralization of argument delimiters in a command ('Argument Injection') issue exists in Defense Platform Home Edition Ver.3.9.51.x and earlier. If an attacker provides specially crafted data to the specific process of the Windows system where the product is running, the system may cause a Blue Screen of Death (BSOD), and as a result, cause a denial-of-service (DoS) condition.
Metrics
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:C/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Hummingheads | Defense Platform | <= 3.9.51.0 |
References
- https://jvn.jp/en/jp/JVN66673020/Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-24845?
How severe is CVE-2025-24845?
How do I fix CVE-2025-24845?
Are you affected by CVE-2025-24845?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
