Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-49148

Опубликовано: 11 июн. 2025
Источник: nvd
CVSS3: 7.3
EPSS Низкий

Описание

ClipShare is a lightweight and cross-platform tool for clipboard sharing. Prior to 3.8.5, ClipShare Server for Windows uses the default Windows DLL search order and loads system libraries like CRYPTBASE.dll and WindowsCodecs.dll from its own directory before the system path. A local, non-privileged user who can write to the folder containing clip_share.exe can place malicious DLLs there, leading to arbitrary code execution in the context of the server, and, if launched by an Administrator (or another elevated user), it results in a reliable local privilege escalation. This vulnerability is fixed in 3.8.5.

EPSS

Процентиль: 2%
0.00015
Низкий

7.3 High

CVSS3

Дефекты

CWE-427

EPSS

Процентиль: 2%
0.00015
Низкий

7.3 High

CVSS3

Дефекты

CWE-427