7.3
/ 10
HIGH
CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Description
Incorrect permission assignment for critical resource issue exists in SS1 Ver.16.0.0.10 and earlier (Media version:16.0.0a and earlier), which may allow users who can log in to a client terminal to obtain root privileges.
Basic Information
ID
CVE-2025-53396
Source
jpcert
Published
Aug 28, 2025 at 08:27
Affected Product
Vendor
DOS Co., Ltd.
Product
SS1
Version
Ver.16.0.0.10 and earlier (Media version:16.0.0a and earlier) (Affected under MacOS environment only)
Affected Versions
DOS Co., Ltd. SS1 Ver.16.0.0.10 and earlier (Media version:16.0.0a and earlier) (Affected under MacOS environment only)
DOS Co., Ltd. SS1 Cloud Ver.2.1.3 and earlier (Affected under MacOS environment only)
DOS Co., Ltd. SS1 Cloud Ver.2.1.3 and earlier (Affected under MacOS environment only)