PT-2025-39638 · Seagate · Seagate Toolkit

·

CVE-2025-9267

·

Published

2025-08-20

·

Updated

2025-09-28

CVSS v4.0

7.0

High

VectorAV:L/AC:L/AT:N/PR:H/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Seagate Toolkit versions prior to 2.35.0.6
Description The software attempts to load DLLs from the current working directory without validating their origin or integrity. This can be exploited by placing a malicious DLL in the same directory as the installer executable, potentially leading to arbitrary code execution with the privileges of the user running the installer. The issue is due to insecure DLL loading practices, such as relying on relative paths when invoking system libraries.
Recommendations Update to version 2.35.0.6 or later.

Exploit

Fix

Untrusted Search Path

Uncontrolled Search Path Element

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-12441
CVE-2025-9267

Affected Products

Seagate Toolkit