CVE-2025-2759

CVE Details

Basic Information

Title CVE-2025-2759
Type cve
Published 2025-05-22T01:15:52
Last Seen 2025-05-22T01:26:09

CVSS Information

Base Score 7.0 (HIGH)
Attack Vector LOCAL
Attack Complexity HIGH
Privileges Required LOW
User Interaction NONE
Scope UNCHANGED
Confidentiality Impact HIGH
Integrity Impact HIGH
Availability Impact HIGH

AI Analysis

AI Description The GStreamer installer has incorrect permissions on folders, allowing local attackers to escalate privileges and execute arbitrary code in the context of a target user. This vulnerability requires the attacker to first obtain low-privileged code execution on the system.
AI Severity High
Vendor GStreamer
Product GStreamer
Affected Version

Additional Information

CVE List CVE-2025-2759
CWE List CWE-732
Bulletin Family cve

Description

GStreamer Incorrect Permission Assignment Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of GStreamer. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.

The specific flaw exists within the product installer. The issue results from incorrect permissions on folders. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of a target user. Was ZDI-CAN-25448.

CVSS Score Summary

Base Score: %!f(string=#) (HIGH)

View Full CVE Details

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.