Data Corruption Vulnerability in Windows Software by Major Vendor
CVE-2025-53947
6.9MEDIUM
What is CVE-2025-53947?
A vulnerability exists within certain Windows software, enabling a local attacker with limited privileges to exploit a flaw resulting in the corruption of sensitive data. This issue arises due to the creation of a data folder that is assigned overly permissive privileges, which permits any user logged into the system to alter its contents unexpectedly. Such exposure can lead to unauthorized modifications that compromise data integrity and confidentiality.
Affected Version(s)
In-Sight 2000 series 5.x <= 6.5.1
In-Sight 7000 series 5.x <= 6.5.1
In-Sight 8000 series 5.x <= 6.5.1
References
CVSS V4
Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Diego Giubertoni of Nozomi Networks reported these vulnerabilities to CISA.