CVE Details
Basic Information
| Title |
CVE-2025-47749 |
| Type |
cve |
| Published |
2025-05-19T08:15:22 |
| Last Seen |
2025-05-19T08:27:46 |
CVSS Information
| Base Score |
7.8 (HIGH) |
| Attack Vector |
LOCAL |
| Attack Complexity |
LOW |
| Privileges Required |
NONE |
| User Interaction |
REQUIRED |
| Scope |
UNCHANGED |
| Confidentiality Impact |
HIGH |
| Integrity Impact |
HIGH |
| Availability Impact |
HIGH |
AI Analysis
| AI Description |
V-SFT v6.2.5.0 and earlier contain a vulnerability in VS6EditData.dll!CWinFontInf::WinFontMsgCheck function where a pointer is not freed correctly. This can be exploited by opening specially crafted V7 or V8 files, leading to a crash or potential code execution. |
| AI Severity |
High |
| Vendor |
Unknown |
| Product |
V-SFT |
| Affected Version |
<= 6.2.5.0 |
Additional Information
| CVE List |
CVE-2025-47749 |
| CWE List |
CWE-761 |
| Bulletin Family |
cve |
Description
V-SFT v6.2.5.0 and earlier contains an issue with free of pointer not at start of buffer in VS6EditData.dll!CWinFontInf::WinFontMsgCheck function. Opening specially crafted V7 or V8 files may lead to crash,…
CVSS Score Summary
Base Score: %!f(string=#) (HIGH)
View Full CVE Details