Arbitrary Code Execution Vulnerability in Thesycon TUSBAudio Installer
CVE-2024-25376

7.8HIGH

What is CVE-2024-25376?

An exploit found in the MSI-based installers of Thesycon's TUSBAudio software allows a local attacker to execute arbitrary code by leveraging the msiexec.exe repair mode. Users should be aware of the risks associated with using affected versions prior to 5.68.0 and take necessary precautions to protect their systems.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.