CVE-2025-13663
Under certain circumstances, the Quartus Prime Pro Installer for Windows does not check the permissions of the Quartus target installation directory if the target installation directory already exists.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.7
- CVSS vector
- CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
- EPSS probability
- 0.10%
- CWE
- CWE-279
- Published
- 2025-12-11
- Last modified
- 2026-03-13
Affected products
- Altera Quartus Prime Pro
Weakness type
Related vulnerabilities
- CVE-2026-46388 — osquery: Unprivileged users can temporarily read file carve contents
- CVE-2026-4948 — Firewalld: firewalld: local unprivileged user can modify firewall state due to d-bus setter mis-authorization
- CVE-2026-20062 — A vulnerability in the CLI of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software in...
- CVE-2025-12801 — Nfs-utils: rpc.mountd in the nfs-utils privilege escalation
- CVE-2025-14025 — Ansible-automation-platform/aap-gateway: aap-gateway: read-only personal access token (pat) bypasses write restrictions
- CVE-2025-36228 — Incorrect Execution-Assigned Permissions in IBM Aspera Faspex
- CVE-2024-25621 — containerd affected by a local privilege escalation via wide permissions on CRI directory
- CVE-2025-30001 — Apache StreamPark: Authenticated users can trigger remote command execution