CVE-2025-1865

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Apr 4, 2025
Updated: Apr 7, 2025
CWE ID 284

Summary

CVE-2025-1865 is a recently disclosed vulnerability affecting a kernel driver. The driver, accessible to low-privileged users, contains a flaw that fails to verify the privileges of the calling process when using a specific function. This oversight enables users to create files in arbitrary locations, thereby gaining full user control. Ultimately, an attacker could exploit this vulnerability to escalate privileges to the SYSTEM level.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Virtual CloneDrive

Affected Vendors

  • Elaborate Bytes AG