PT-2025-3895 · Libretro · Retroarch

Havook

·

Published

2025-01-14

·

Updated

2025-01-18

·

CVE-2025-0459

CVSS v2.0

4.3

Medium

VectorAV:L/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions libretro RetroArch versions up to 1.19.1
Description A problematic issue has been found in the library profapi.dll of the component Startup, leading to an untrusted search path. The manipulation requires a local attack approach. The vendor was contacted about this disclosure but did not respond.
Recommendations For versions up to 1.19.1, as a temporary workaround, consider restricting access to the profapi.dll library to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Untrusted Search Path

Weakness Enumeration

Related Identifiers

CVE-2025-0459

Affected Products

Retroarch