PT-2025-31970 · Mitsubishi · Iconics Genesis64+4

Published

2025-08-05

·

Updated

2026-04-08

·

CVE-2025-7376

CVSS v3.1

5.9

Medium

VectorAV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Mitsubishi Electric Iconics Digital Solutions GENESIS64 all versions Mitsubishi Electric Iconics Digital Solutions GENESIS version 11.00 Mitsubishi Electric GENESIS64 all versions Mitsubishi Electric MC Works64 all versions Mitsubishi Electric GENESIS version 11.00
Description A Windows Shortcut Following (.LNK) issue exists in multiple processes of Mitsubishi Electric Iconics Digital Solutions GENESIS64, Mitsubishi Electric Iconics Digital Solutions GENESIS version 11.00, Mitsubishi Electric GENESIS64, Mitsubishi Electric MC Works64, and Mitsubishi Electric GENESIS version 11.00. A local authenticated attacker can make an unauthorized write to arbitrary files by creating a symbolic link from a file used as a write destination by the processes of the affected products to a target file. This could allow the attacker to destroy the file on a PC with the affected products installed, resulting in a denial-of-service (DoS) condition on the PC if the destroyed file is necessary for the operation of the PC.
Recommendations For Mitsubishi Electric Iconics Digital Solutions GENESIS64 all versions, update to a newer version that contains a fix for this issue. For Mitsubishi Electric Iconics Digital Solutions GENESIS version 11.00, update to a newer version that contains a fix for this issue. For Mitsubishi Electric GENESIS64 all versions, update to a newer version that contains a fix for this issue. For Mitsubishi Electric MC Works64 all versions, update to a newer version that contains a fix for this issue. For Mitsubishi Electric GENESIS version 11.00, update to a newer version that contains a fix for this issue.

Fix

DoS

Weakness Enumeration

Related Identifiers

BDU:2025-09642
CVE-2025-7376

Affected Products

Genesis
Genesis64
Iconics Genesis
Iconics Genesis64
Mc Works64