PT-2025-43983 · Unknown · Easywork Enterprise

Published

2025-10-27

·

Updated

2025-10-27

·

CVE-2025-60791

CVSS v3.1

6.2

Medium

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Easywork Enterprise version 2.1.3.354
Description Easywork Enterprise version 2.1.3.354 exhibits a security issue related to the cleartext storage of sensitive information in memory. Specifically, valid device-bound license keys remain in process memory even after a failed activation attempt. These keys can be retrieved by attaching a debugger or analyzing a process/memory dump. Subsequently, these obtained keys can be used to activate the software on the same machine without a valid purchase.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

CVE-2025-60791

Affected Products

Easywork Enterprise