A low privileged remote attacker may be able to disclose confidential information from the memory of a privileged process by sending specially crafted calls to the Device Manager web service that cause an out-of-bounds read operation under certain circumstances due to ASLR and thereby potentially copy confidential information into a response.
References
| Link | Resource |
|---|---|
| https://certvde.com/de/advisories/VDE-2025-092 |
Configurations
No configuration.
History
27 Jan 2026, 12:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-01-27 12:15
Updated : 2026-01-27 14:59
NVD link : CVE-2025-41728
Mitre link : CVE-2025-41728
CVE.ORG link : CVE-2025-41728
JSON object : View
Products Affected
No product.
CWE
CWE-125
Out-of-bounds Read
