CVE-2025-0425
Via the GUI of the "bestinformed Infoclient", a low-privileged user is by default able to change the server address of the "bestinformed Server" to which this client connects. This is dangerous as the "bestinformed Infoclient" runs with elevated permissions ("nt authority\system"). By changing the server address to a malicious server, or a script simulating a server, the user is able to escalate his privileges by abusing certain features of the "bestinformed Web" server. Those features include: * Pushing of malicious update packages * Arbitrary Registry Read as "nt authority\system" An attacker is able to escalate his privileges to "nt authority\system" on the Windows client running the "bestinformed Infoclient". This attack is not possible if a custom configuration ("Infoclient.ini") containing the flags "ShowOnTaskbar=false" or "DisabledItems=stPort,stAddress" is deployed.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.5
- CVSS vector
- CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
- EPSS probability
- 0.17%
- CWE
- CWE-15
- Published
- 2025-02-18
- Last modified
- 2026-03-13
Affected products
- Cordaware bestinformed Infoclient
- Cordaware bestinformed Infoclient
Weakness type
Related vulnerabilities
- CVE-2026-19592 — OpenAI Codex CLI for Windows, macOS, and Linux and Codex Desktop for Windows and macOS...
- CVE-2026-19593 — OpenAI Codex Desktop for Windows and macOS automatically inspected Git metadata and working-tree...
- CVE-2026-16708 — IBM Db2 Mirror for i is affected by multiple vulnerabilities
- CVE-2026-19884 — In Eclipse Theia versions up to and including 1.69.0, opening a folder starts source control...
- CVE-2026-73661 — FreePBX: Authenticated Framework AUTHTYPE Can Be Restored From a Crafted Backup
- CVE-2026-66065 — Ouroboros: Untrusted project .env can still reach RCE via omitted execution-routing keys (Incomplete fix of CVE-2026-47211)
- CVE-2026-56567 — HCL iControl is affected by multiple security vulnerabilities.
- CVE-2026-46485 — Dash: Users can write to config despire permissions (OIDC tested)