CVE-2025-13433

A security flaw has been discovered in Muse Group MuseHub 2.1.0.1567. The affected element is an unknown function of the file C:\Program Files\WindowsApps\Muse.MuseHub_2.1.0.1567_x64__rb9pth70m6nz6\Muse.Updater.exe of the component Windows Service. The manipulation results in unquoted search path. The attack is only possible with local access. A high complexity level is associated with this attack. The exploitability is described as difficult. The vendor was contacted early about this disclosure but did not respond in any way.
Configurations

No configuration.

History

20 Nov 2025, 15:17

Type Values Removed Values Added
New CVE

Information

Published : 2025-11-20 15:17

Updated : 2025-11-20 15:17


NVD link : CVE-2025-13433

Mitre link : CVE-2025-13433

CVE.ORG link : CVE-2025-13433


JSON object : View

Products Affected

No product.

CWE
CWE-426

Untrusted Search Path

CWE-428

Unquoted Search Path or Element