CVE-2025-69689

high

Description

The Fan Control application V251 contains an improper privilege handling vulnerability in its Open File Dialog. The dialog processes user-supplied paths with elevated permissions, which can be exploited by a local attacker to perform actions with administrator-level privileges.

References

https://github.com/Rem0o/FanControl.Releases/releases/tag/V251

https://github.com/Rem0o/FanControl.Releases

https://gist.github.com/ahrixia/7c89bb3f1af6e85aeedde5ddb557a529

https://getfancontrol.com

Details

Source: Mitre, NVD

Published: 2026-04-27

Updated: 2026-04-27

Risk Information

CVSS v2

Base Score: 6.8

Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

Severity: Medium

CVSS v3

Base Score: 8.8

Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Severity: High