CVE-2025-4532

A vulnerability classified as critical has been found in Shanghai Bairui Information Technology SunloginClient 15.8.3.19819. This affects an unknown part in the library process.dll of the file sunlogin_guard.exe. The manipulation leads to uncontrolled search path. Local access is required to approach this attack. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Configurations

No configuration.

History

12 May 2025, 17:32

Type Values Removed Values Added
Summary
  • (es) Se ha detectado una vulnerabilidad crítica en Shanghai Bairui Information Technology SunloginClient 15.8.3.19819. Esta vulnerabilidad afecta a una parte desconocida de la librería process.dll del archivo sunlogin_guard.exe. La manipulación genera una ruta de búsqueda incontrolada. Se requiere acceso local para este ataque. La complejidad del ataque es bastante alta. Se considera que su explotabilidad es difícil. Se ha hecho público el exploit y puede que sea utilizado. Se contactó al proveedor con antelación para informarle sobre esta divulgación, pero no respondió.

11 May 2025, 06:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-11 06:15

Updated : 2025-05-12 17:32


NVD link : CVE-2025-4532

Mitre link : CVE-2025-4532

CVE.ORG link : CVE-2025-4532


JSON object : View

Products Affected

No product.

CWE
CWE-426

Untrusted Search Path

CWE-427

Uncontrolled Search Path Element