Insecure Deserialization Vulnerability in WinMatrix3 by Simopro Technology
CVE-2025-7916
9.3CRITICAL
What is CVE-2025-7916?
WinMatrix3, a product developed by Simopro Technology, contains an Insecure Deserialization vulnerability that enables unauthenticated remote attackers to execute arbitrary code on the server. By delivering specially crafted serialized content, an attacker can manipulate the organization's application environment, potentially leading to unauthorized access and exploitation of sensitive data. It is crucial for users of WinMatrix3 to implement immediate remediation measures to protect their systems from potential unauthorized actions.
Affected Version(s)
WinMatrix3 0 <= 3.8.52.5