CVE-2025-35471 Information
May 14, 2025
cve
Description
conda-forge openssl-feedstock before 066e83c (2024-05-20) on Microsoft Windows configures OpenSSL to use an OPENSSLDIR file path that can be written to by non-privilged local users. By writing a specially crafted openssl.cnf file in OPENSSLDIR a non-privileged local user can execute arbitrary code with the privileges of the user or process loading openssl-feedstock DLLs. Miniforge before 24.5.0 is also affected.
Reference
https://github.com/conda-forge/openssl-feedstock/commit/066e83c5226bafe90a9c0575b077ce30cd5f5921 url https://github.com/conda-forge/openssl-feedstock/issues/201 url
Share on: