CVE-2025-67905 - CERT CVE
ID CVE-2025-67905
Sažetak Malwarebytes AdwCleaner before v.8.7.0 runs as Administrator and performs an insecure log file delete operation in which the target location is user-controllable, allowing a non-admin user to escalate privileges to SYSTEM via a symbolic link, a related issue to CVE-2023-28892. To exploit this, an attacker must create a file in a given folder path and intercept the application log file deletion flow.
Reference
CVSS
Base: 8.7
Impact: 6.0
Exploitability:2.0
Pristup
VektorSloženostAutentikacija
LOCAL LOW LOW
Impact
PovjerljivostCjelovitostDostupnost
HIGH HIGH LOW
CVSS vektor CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L
Zadnje važnije ažuriranje 18-02-2026 - 17:52
Objavljeno 17-02-2026 - 17:21