CVE-2025-22894

medium

Description

Unprotected Windows messaging channel ('Shatter') issue exists in Defense Platform Home Edition Ver.3.9.51.x and earlier. If an attacker sends a specially crafted message to the specific process of the Windows system where the product is running, arbitrary files in the system may be altered. As a result, an arbitrary DLL may be executed with SYSTEM privilege.

References

https://www.hummingheads.co.jp/dep/storelist/

https://jvn.jp/en/jp/JVN66673020/

Details

Source: Mitre, NVD

Published: 2025-02-06

Updated: 2025-02-06

Risk Information

CVSS v2

Base Score: 4.6

Vector: CVSS2#AV:L/AC:L/Au:S/C:N/I:C/A:N

Severity: Medium

CVSS v3

Base Score: 6.5

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N

Severity: Medium

EPSS

EPSS: 0.00015