Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 24 Nov 2025 09:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Microsoft
Microsoft windows Muse Muse musehub |
|
| Vendors & Products |
Microsoft
Microsoft windows Muse Muse musehub |
Thu, 20 Nov 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 20 Nov 2025 00:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A security flaw has been discovered in Muse Group MuseHub 2.1.0.1567. The affected element is an unknown function of the file C:\Program Files\WindowsApps\Muse.MuseHub_2.1.0.1567_x64__rb9pth70m6nz6\Muse.Updater.exe of the component Windows Service. The manipulation results in unquoted search path. The attack is only possible with local access. A high complexity level is associated with this attack. The exploitability is described as difficult. The vendor was contacted early about this disclosure but did not respond in any way. | |
| Title | Muse Group MuseHub Windows Service Muse.Updater.exe unquoted search path | |
| Weaknesses | CWE-426 CWE-428 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2025-11-20T15:30:36.998Z
Reserved: 2025-11-19T16:52:41.302Z
Link: CVE-2025-13433
Updated: 2025-11-20T15:30:33.377Z
Status : Deferred
Published: 2025-11-20T15:17:24.337
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-13433
No data.
OpenCVE Enrichment
Updated: 2025-11-24T09:11:02Z