CNNVD-202510-4018 Information

CNNVD ID

CNNVD-202510-4018

CVE-2025-61161

  • CNNVD Published: 2025-10-29

Description (Chinese)

Evope Collector是巴西Evope公司的一个团队绩效监控与任务挖掘平台。 Evope Collector 1.1.6.9.0版本存在安全漏洞,该漏洞源于从不受控制的搜索路径加载wtsapi32.dll库,可能导致本地攻击者执行任意代码或提升权限至SYSTEM。

Description (English)

Evope Collector is a team performance monitoring and mission exhumation platform for Evope Brazil. Evope Collator 1.1.6.9.0 has a security loophole, which originates in the loading of wtsapi32.dll vaults from uncontrolled search paths, which could lead local attackers to enforce arbitrary codes or upgrade access to SYSTEM.

Hazard Level

Medium

Vulnerability Type

其他

Affected Vendor

Evope

Published

2025-10-29

Last Modified

2026-02-24

References

https://www.evope.tech/ https://xavilok.es/dll-hijacking-in-evopeservice–system-to-gui-shell https://access.redhat.com/security/cve/cve-2025-61161

Share on: