PT-2025-32303 · Unknown+1 · Gpmaw3.Exe+3

Lukesec

·

Published

2025-08-07

·

Updated

2025-08-07

·

CVE-2025-50675

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions GPMAW 14 (affected versions not specified)
Description GPMAW 14, a bioinformatics software, exhibits a critical issue stemming from insecure file permissions within its installation directory. The directory allows all users full read, write, and execute permissions, enabling manipulation of files, including executables such as GPMAW3.exe, Fragment.exe, and the uninstaller GPsetup64 17028.exe. An attacker with user-level access can replace or modify the uninstaller with a malicious version. Because the uninstaller is executed with administrative privileges, this could lead to privilege escalation and arbitrary code execution in the context of an administrator.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

LPE

Incorrect Permission

Weakness Enumeration

Related Identifiers

CVE-2025-50675

Affected Products

Fragment.Exe
Gpmaw 14
Gpmaw3.Exe
Gpsetup64 17028.Exe