CVE 8.4 HIGH

Local Privilege Escalation in dormakaba Kaba exos 9300 System management_CVE-2025-59094

8.4 / 10
HIGH
CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Description

A local privilege escalation vulnerability has been identified in the Kaba exos 9300 System management application (d9sysdef.exe). Within this application it is possible to specify an arbitrary executable as well as the weekday and start time, when the specified executable should be run with SYSTEM privileges.

Basic Information

ID CVE-2025-59094
Source SEC-VLab
Published Jan 26, 2026 at 10:04

Affected Product

Vendor dormakaba
Product Kaba exos 9300
Version All versions, manual mitigation needed!
Affected Versions dormakaba Kaba exos 9300 All versions, manual mitigation needed!

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.