Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-14377 | conda-forge openssl-feedstock before 066e83c (2024-05-20), on Microsoft Windows, configures OpenSSL to use an OPENSSLDIR file path that can be written to by non-privilged local users. By writing a specially crafted openssl.cnf file in OPENSSLDIR, a non-privileged local user can execute arbitrary code with the privileges of the user or process loading openssl-feedstock DLLs. Miniforge before 24.5.0 is also affected. |
Tue, 23 Sep 2025 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Conda-forge
Conda-forge miniforge Conda-forge openssl-feedstock Microsoft Microsoft windows |
|
| CPEs | cpe:2.3:a:conda-forge:miniforge:*:*:*:*:*:*:*:* cpe:2.3:a:conda-forge:openssl-feedstock:*:*:*:*:*:*:*:* cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:* |
|
| Vendors & Products |
Conda-forge
Conda-forge miniforge Conda-forge openssl-feedstock Microsoft Microsoft windows |
Thu, 22 May 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 13 May 2025 01:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | conda-forge openssl-feedstock before 066e83c (2024-05-20), on Microsoft Windows, configures OpenSSL to use an OPENSSLDIR file path that can be written to by non-privilged local users. By writing a specially crafted openssl.cnf file in OPENSSLDIR, a non-privileged local user can execute arbitrary code with the privileges of the user or process loading openssl-feedstock DLLs. Miniforge before 24.5.0 is also affected. | |
| Title | conda-forge openssl-feedstock writable OPENSSLDIR | |
| Weaknesses | CWE-427 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: cisa-cg
Published:
Updated: 2025-05-22T19:32:45.353Z
Reserved: 2025-04-15T20:57:14.283Z
Link: CVE-2025-35471
Updated: 2025-05-22T19:32:40.289Z
Status : Analyzed
Published: 2025-05-13T02:15:17.607
Modified: 2025-09-23T15:47:38.477
Link: CVE-2025-35471
No data.
OpenCVE Enrichment
No data.
EUVD