PT-2025-14872 · Elaborate Bytes Ag · Virtual Clonedrive

Neodyme Ag

·

Published

2025-04-04

·

Updated

2025-07-07

·

CVE-2025-1865

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions The product name cannot be determined.
Description The issue concerns a kernel driver that is accessible to low-privileged users. This driver exposes a function that fails to properly validate the privileges of the calling process, allowing for the creation of files at arbitrary locations with full user control. This ultimately enables privilege escalation to SYSTEM.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

LPE

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2025-1865

Affected Products

Virtual Clonedrive