Vulnerability Description
CYRISMA Sensor before 444 for Windows has an Insecure Folder and File Permissions vulnerability. A low-privileged user can abuse these issues to escalate privileges and execute arbitrary code in the context of NT AUTHORITY\SYSTEM by replacing DataSpotliteAgent.exe or any other binaries called by the Cyrisma_Agent service when it starts
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://msry1.gitbook.io/thegoldenrecord/blog/vulnerability-and-bug-disclosures/
- https://youtu.be/2DScqXPtrWw
- https://msry1.gitbook.io/thegoldenrecord/blog/vulnerability-and-bug-disclosures/
FAQ
What is CVE-2025-57625?
CVE-2025-57625 is a vulnerability with a CVSS score of 8.8 (HIGH). CYRISMA Sensor before 444 for Windows has an Insecure Folder and File Permissions vulnerability. A low-privileged user can abuse these issues to escalate privileges and execute arbitrary code in the c...
How severe is CVE-2025-57625?
CVE-2025-57625 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-57625?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.