File Overwrite Vulnerability in HPE Aruba Networking VIA Client
CVE-2025-25041

5.5MEDIUM

Key Information:

Vendor
HP (HP)
Status
Virtual Intranet Access (via)
Vendor
CVE Published:
1 April 2025

Summary

A vulnerability in the HPE Aruba Networking Virtual Intranet Access (VIA) client permits malicious users to overwrite arbitrary files, potentially gaining access as NT AUTHORITY\SYSTEM on the Microsoft Windows Operating System. Successful exploitation of this vulnerability may lead to a Denial-of-Service (DoS) condition. Notably, this issue is exclusive to Windows clients and does not impact Linux and Android platforms. Organizations using the affected VIA client should implement security measures to mitigate potential risks.

Affected Version(s)

Virtual Intranet Access (VIA) Windows 4.0.0 <= 4.7.0

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Gee-netics
.