CVE-2025-41728

A low privileged remote attacker may be able to disclose confidential information from the memory of a privileged process by sending specially crafted calls to the Device Manager web service that cause an out-of-bounds read operation under certain circumstances due to ASLR and thereby potentially copy confidential information into a response.
Configurations

No configuration.

History

15 Apr 2026, 00:35

Type Values Removed Values Added
Summary
  • (es) Un atacante remoto con privilegios bajos podría divulgar información confidencial de la memoria de un proceso privilegiado enviando llamadas especialmente diseñadas al servicio web del Administrador de dispositivos que causan una operación de lectura fuera de límites bajo ciertas circunstancias debido a ASLR y, por lo tanto, copiar potencialmente información confidencial en una respuesta.

27 Jan 2026, 12:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-27 12:15

Updated : 2026-06-17 09:23


NVD link : CVE-2025-41728

Mitre link : CVE-2025-41728

CVE.ORG link : CVE-2025-41728


JSON object : View

Products Affected

No product.

CWE
CWE-125

Out-of-bounds Read