Vulnerabilities (CVE)

Filtered by CWE-422
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-22894 2025-02-06 N/A 6.5 MEDIUM
Unprotected Windows messaging channel ('Shatter') issue exists in Defense Platform Home Edition Ver.3.9.51.x and earlier. If an attacker sends a specially crafted message to the specific process of the Windows system where the product is running, arbitrary files in the system may be altered. As a result, an arbitrary DLL may be executed with SYSTEM privilege.
CVE-2025-20094 2025-02-06 N/A 8.8 HIGH
Unprotected Windows messaging channel ('Shatter') issue exists in Defense Platform Home Edition Ver.3.9.51.x and earlier. If an attacker sends a specially crafted message to the specific process of the Windows system where the product is running, arbitrary code may be executed with SYSTEM privilege.