PT-2025-5803 · Microsoft · Windows
Taizoh Tsukamoto
·
Published
2025-02-06
·
Updated
2026-02-04
·
CVE-2025-20094
CVSS v3.1
8.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Defense Platform Home Edition versions 3.9.51.x and earlier
Description:
The issue exists due to an unprotected Windows messaging channel, also known as 'Shatter'. If an attacker sends a specially crafted message to the specific process of the Windows system where the product is running, arbitrary code may be executed with SYSTEM privilege.
Recommendations:
For Defense Platform Home Edition versions 3.9.51.x and earlier, consider disabling the Windows messaging channel as a temporary workaround until a patch is available. Restrict access to the specific process of the Windows system where the product is running to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Windows