CVE-2025-58742

Insufficiently Protected Credentials, Improper Restriction of Communication Channel to Intended Endpoints vulnerability in the Connection Settings dialog in Milner ImageDirector Capture on Windows allows Adversary in the Middle (AiTM) by modifying the 'Server' field to redirect client authentication.This issue affects ImageDirector Capture: from 7.0.9 before 7.6.3.25808.
References
Link Resource
https://sra.io/advisories Third Party Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:milner:imagedirector_capture:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

History

17 Jun 2026, 09:44

Type Values Removed Values Added
Summary
  • (es) Credenciales Insuficientemente Protegidas, Restricción Inadecuada del Canal de Comunicación a los Puntos Finales Previstos vulnerabilidad en el diálogo de Configuración de Conexión en Milner ImageDirector Capture en Windows permite Adversario en el Medio (AiTM) al modificar el campo 'Servidor' para redirigir la autenticación del cliente. Este problema afecta a ImageDirector Capture: desde 7.0.9 antes de 7.6.3.25808.

10 Feb 2026, 16:51

Type Values Removed Values Added
First Time Milner imagedirector Capture
Milner
Microsoft
Microsoft windows
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.9
CPE cpe:2.3:a:milner:imagedirector_capture:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
References () https://sra.io/advisories - () https://sra.io/advisories - Third Party Advisory

20 Jan 2026, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-20 22:15

Updated : 2026-06-17 09:44


NVD link : CVE-2025-58742

Mitre link : CVE-2025-58742

CVE.ORG link : CVE-2025-58742


JSON object : View

Products Affected

microsoft

  • windows

milner

  • imagedirector_capture
CWE
CWE-522

Insufficiently Protected Credentials

CWE-923

Improper Restriction of Communication Channel to Intended Endpoints