PT-2025-47544 · Muse · Musehub
Lakshay12311
·
Published
2025-11-20
·
Updated
2025-11-20
·
CVE-2025-13433
CVSS v3.1
7.0
High
| Vector | AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Muse Group MuseHub version 2.1.0.1567
Description
A security flaw exists in Muse Group MuseHub. The issue involves an unquoted search path within the file C:Program FilesWindowsAppsMuse.MuseHub 2.1.0.1567 x64 rb9pth70m6nz6Muse.Updater.exe, specifically within a component of the Windows Service. Exploitation requires local access and is considered difficult due to a high complexity level. The vendor was contacted regarding this disclosure but did not provide a response.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
LPE
Untrusted Search Path
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Musehub