Insecure Deserialization Vulnerability in WinMatrix3 by Simopro Technology
CVE-2025-7916

9.3CRITICAL

Key Information:

Vendor
CVE Published:
21 July 2025

What is CVE-2025-7916?

WinMatrix3, a product developed by Simopro Technology, contains an Insecure Deserialization vulnerability that enables unauthenticated remote attackers to execute arbitrary code on the server. By delivering specially crafted serialized content, an attacker can manipulate the organization's application environment, potentially leading to unauthorized access and exploitation of sensitive data. It is crucial for users of WinMatrix3 to implement immediate remediation measures to protect their systems from potential unauthorized actions.

Affected Version(s)

WinMatrix3 0 <= 3.8.52.5

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-7916 : Insecure Deserialization Vulnerability in WinMatrix3 by Simopro Technology