A low privileged remote attacker can execute arbitrary code by sending specially crafted calls to the web service of the Device Manager or locally via an API and can cause integer overflows which then may lead to arbitrary code execution within privileged processes.
References
| Link | Resource |
|---|---|
| https://certvde.com/de/advisories/VDE-2025-092 |
Configurations
No configuration.
History
27 Jan 2026, 12:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-01-27 12:15
Updated : 2026-01-27 14:59
NVD link : CVE-2025-41726
Mitre link : CVE-2025-41726
CVE.ORG link : CVE-2025-41726
JSON object : View
Products Affected
No product.
CWE
CWE-190
Integer Overflow or Wraparound
