PT-2025-43983 · Unknown · Easywork Enterprise
Published
2025-10-27
·
Updated
2025-10-27
·
CVE-2025-60791
CVSS v3.1
6.2
Medium
| Vector | AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Easywork Enterprise version 2.1.3.354
Description
Easywork Enterprise version 2.1.3.354 exhibits a security issue related to the cleartext storage of sensitive information in memory. Specifically, valid device-bound license keys remain in process memory even after a failed activation attempt. These keys can be retrieved by attaching a debugger or analyzing a process/memory dump. Subsequently, these obtained keys can be used to activate the software on the same machine without a valid purchase.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Easywork Enterprise