PT-2025-22922 · Wondershare+1 · Wondershare Filmora+2

Shellkraft

·

Published

2025-05-26

·

Updated

2025-05-31

·

CVE-2025-5180

CVSS v3.1

7.3

High

VectorAV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Wondershare Filmora version 14.5.16
Description A critical vulnerability has been found in Wondershare Filmora, affecting some unknown functionality in the library CRYPTBASE.dll of the file NFWCHK.exe of the component Installer. The manipulation leads to uncontrolled search path. Attacking locally is a requirement. The complexity of an attack is rather high, and the exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond.
Recommendations For Wondershare Filmora version 14.5.16, as a temporary workaround, consider restricting access to the vulnerable library CRYPTBASE.dll until a patch is available. Additionally, avoid using the affected Installer component until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Untrusted Search Path

Uncontrolled Search Path Element

Weakness Enumeration

Related Identifiers

CVE-2025-5180

Affected Products

Cryptbase.Dll
Nfwchk.Exe
Wondershare Filmora