Release Notes
v1.0
Search this version
Release Notes
Release Notes
Security SDK
AppRemover
V3V4 Adapter
VModSource
Page
Code Steps
Category
Label
Link
Separator
Title
Message
Page icon
No icon. This page keeps the plain index row.
orSVG or PNG, square, at least 32×32.
Create new category
What is the title of your new category?
Edit page index title
What is the title of the page index?
Edit category
What is the new title of your category?
Edit link
What is the new title and URL of your link?
CVE-2025-0131
Copy Markdown
Open in ChatGPT
Open in Claude
Description
An incorrect privilege management vulnerability in the OPSWAT MetaDefender Endpoint Security SDK on Windows devices allows a locally authenticated non-administrative Windows user to escalate their privileges to NT AUTHORITY\SYSTEM. However, execution requires that the local user also successfully exploits a race condition, which makes this vulnerability difficult to exploit.
References
https://www.opswat.com/products/metadefender/endpoint-security-sdk
Severity
CVSS-BT: 4.0
CVSS-B: 7.1
Vector: CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:H/SI:H/SA:H/E:U/AU:N/R:U/V:D/U:Amber
Weakness Enumeration
CWE-266: Incorrect Privilege Assignment
CAPEC-233 Privilege Escalation
Known Software Configurations
MetaDefender Endpoint Security SDK version up-to (by excluding) 4.3.4451.0 (published January 21st, 2025).
Discoverer
Last updated by Morrissey on May 15, 2025
Was this page helpful?
null
Discard Changes
Do you want to discard your current changes and overwrite with the template?
Archive Synced Block
Message
Create new Template
What is this template's title?
Delete Template
Message