CVE-2025-24845

Improper neutralization of argument delimiters in a command ('Argument Injection') issue exists in Defense Platform Home Edition Ver.3.9.51.x and earlier. If an attacker provides specially crafted data to the specific process of the Windows system where the product is running, the system may cause a Blue Screen of Death (BSOD), and as a result, cause a denial-of-service (DoS) condition.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:hummingheads:defense_platform:*:*:*:*:home:*:*:*

History

30 Jan 2026, 21:05

Type Values Removed Values Added
First Time Hummingheads
Hummingheads defense Platform
CVSS v2 : unknown
v3 : 6.3
v2 : unknown
v3 : 5.5
References () https://jvn.jp/en/jp/JVN66673020/ - () https://jvn.jp/en/jp/JVN66673020/ - Third Party Advisory
References () https://www.hummingheads.co.jp/dep/storelist/ - () https://www.hummingheads.co.jp/dep/storelist/ - Product
CPE cpe:2.3:a:hummingheads:defense_platform:*:*:*:*:home:*:*:*
Summary
  • (es) Existe un problema de neutralización incorrecta de los delimitadores de argumentos en un comando ('Inyección de argumentos') en Defense Platform Home Edition Ver.3.9.51.x y versiones anteriores. Si un atacante proporciona datos especialmente manipulados al proceso específico del sistema Windows donde se ejecuta el producto, el sistema puede provocar una pantalla azul de la muerte (BSOD) y, como resultado, provocar una condición de denegación de servicio (DoS).

06 Feb 2025, 08:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-06 08:15

Updated : 2026-01-30 21:05


NVD link : CVE-2025-24845

Mitre link : CVE-2025-24845

CVE.ORG link : CVE-2025-24845


JSON object : View

Products Affected

hummingheads

  • defense_platform
CWE
CWE-88

Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')