8.4
/ 10
HIGH
CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Description
A local privilege escalation vulnerability has been identified in the Kaba exos 9300 System management application (d9sysdef.exe). Within this application it is possible to specify an arbitrary executable as well as the weekday and start time, when the specified executable should be run with SYSTEM privileges.
Basic Information
ID
CVE-2025-59094
Source
SEC-VLab
Published
Jan 26, 2026 at 10:04
Affected Product
Vendor
dormakaba
Product
Kaba exos 9300
Version
All versions, manual mitigation needed!
Affected Versions
dormakaba Kaba exos 9300 All versions, manual mitigation needed!