Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Lukesec

#32804of 53,624
7.8Total CVSS
Vulnerabilities · 1
PT-2025-32303
7.8
2025-08-07
Unknown · Gpmaw3.Exe · CVE-2025-50675
**Name of the Vulnerable Software and Affected Versions** GPMAW 14 (affected versions not specified) **Description** GPMAW 14, a bioinformatics software, exhibits a critical issue stemming from insecure file permissions within its installation directory. The directory allows all users full read, write, and execute permissions, enabling manipulation of files, including executables such as `GPMAW3.exe`, `Fragment.exe`, and the uninstaller `GPsetup64 17028.exe`. An attacker with user-level access can replace or modify the uninstaller with a malicious version. Because the uninstaller is executed with administrative privileges, this could lead to privilege escalation and arbitrary code execution in the context of an administrator. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.