PT-2025-26951 · Trellix · System Information Reporter
Ncia Researchers
·
Published
2025-06-26
·
Updated
2026-02-11
·
CVE-2025-3771
CVSS v4.0
7.2
High
| Vector | AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:H/VA:H/SC:L/SI:H/SA:H |
Name of the Vulnerable Software and Affected Versions:
System Information Reporter versions 1.0.3 and prior
Description:
The issue allows a local user to manipulate the location of registry backup files by creating a junction symlink, potentially overwriting system files. This can be achieved by adding a malicious entry to the registry or via policy, which may cause a system crash. An authenticated non-admin local user can exploit this to access files they would not normally have permission to access.
Recommendations:
For System Information Reporter versions 1.0.3 and prior, consider restricting access to the registry under the Trellix SIR registry folder to minimize the risk of exploitation.
As a temporary workaround, avoid using junction symbolic links in the System Information Reporter until a patch is available.
Restrict access to system files that the user would not normally have permission to access to prevent potential overwrites.
Fix
Link Following
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
System Information Reporter