Incorrect default permissions issue in PC Time Tracer prior to 5.2. If exploited, arbitrary code may be executed with SYSTEM privilege on Windows system where the product is running by a local authenticated attacker.
History

Tue, 03 Jun 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 03 Jun 2025 08:15:00 +0000

Type Values Removed Values Added
Description Incorrect default permissions issue in PC Time Tracer prior to 5.2. If exploited, arbitrary code may be executed with SYSTEM privilege on Windows system where the product is running by a local authenticated attacker.
Weaknesses CWE-276
References
Metrics cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 7, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: jpcert

Published: 2025-06-03T08:09:47.909Z

Updated: 2025-06-03T13:54:42.604Z

Reserved: 2025-05-28T02:51:59.281Z

Link: CVE-2025-46355

cve-icon Vulnrichment

Updated: 2025-06-03T13:54:35.373Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-06-03T08:15:19.813

Modified: 2025-06-04T14:54:33.783

Link: CVE-2025-46355

cve-icon Redhat

No data.