Code Execution Vulnerability in Delta Electronics DIAScreen Product
CVE-2025-59300
6.8MEDIUM
What is CVE-2025-59300?
Delta Electronics DIAScreen is vulnerable due to inadequate validation of user-supplied files. This flaw allows an attacker to execute arbitrary code within the context of the currently running process when a user opens a specially crafted malicious file. Proper security measures must be implemented to mitigate the risk associated with this vulnerability.
Affected Version(s)
DIAScreen Windows 0 < 1.6.1
References
CVSS V4
Score:
6.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Natnael Samson working with Trend Micro Zero Day Initiative
Kevin Harwood of CISA