PT-2025-41916 · Microsoft+1 · Installer+1
Published
2025-10-14
·
Updated
2025-10-14
·
CVE-2025-9067
CVSS v4.0
8.5
High
| Vector | AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
FTLinx versions (affected versions not specified)
Description
A security issue exists in the x86 Microsoft Installer (MSI) used with FTLinx. Authenticated attackers with valid Windows user credentials can initiate a repair and hijack the resulting console window. This allows launching a command prompt running with SYSTEM-level privileges, granting full access to all files, processes, and system resources. The attack requires valid Windows user credentials.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
LPE
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ftlinx
Installer