Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 30 Oct 2025 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Evope
Evope collector |
|
| Vendors & Products |
Evope
Evope collector |
Wed, 29 Oct 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-427 | |
| Metrics |
cvssV3_1
|
Wed, 29 Oct 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | DLL hijacking vulnerability in Evope Collector 1.1.6.9.0 and related components load the wtsapi32.dll library from an uncontrolled search path (C:\ProgramData\Evope). This allows local unprivileged attackers to execute arbitrary code or escalate privileges to SYSTEM by placing a crafted DLL in that location. The vulnerable component is Evope.Service.exe, which runs with SYSTEM privileges and automatically loads the DLL on startup or reboot. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-10-29T14:24:37.110Z
Reserved: 2025-09-26T00:00:00.000Z
Link: CVE-2025-61161
Updated: 2025-10-29T14:22:30.495Z
Status : Deferred
Published: 2025-10-29T14:15:56.670
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-61161
No data.
OpenCVE Enrichment
Updated: 2025-10-30T14:38:30Z