CVE-2025-20657

CVSS 3.1 Score 6.7 of 10 (medium)

Details

Published Apr 7, 2025
Updated: Apr 18, 2025
CWE ID 787

Summary

CVE-2025-20657 is a vulnerability affecting the vdec component, where improper input validation allows for a permission bypass. This issue could potentially enable local privilege escalation for an attacker who has already obtained System privileges. User interaction is not needed for exploitation. The patch ID for mitigation is ALPS09486425, and the issue has been identified as MSV-2609.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share