9.8
/ 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Description
SQLite 'sqldiff.exe' does not securely handle the way the Microsoft Windows C runtime converts Unicode characters to ANSI codepages. An attacker could use the '-L' option to load an arbitrary DLL with a crafted command line argument string that results in command line file arguments being misinterpreted as command line options. Fixed on or around 2025-12-26.
AI Analysis
SQLite sqldiff remote code execution vulnerability via argument injection
Basic Information
ID
CVE-2025-71316
Source
cisa-cg
Published
Jun 4, 2026 at 17:39
Modified
Jun 4, 2026 at 19:14
Affected Product
Vendor
SQLite
Product
sqldiff
Affected Versions
SQLite sqldiff 0
CWE Classification
AI Assessment
AI Score
9.8 / 10
AI Severity
Critical
Vendor
SQLite
Product
sqldiff
References
- sqlite.org /src/file/tool/winmain.c
- learn.microsoft.com /en-us/windows/win32/api/processenv/nf-processenv-getcommandlinea
- i.blackhat.com /EU-24/Presentations/EU-24-Tsai-V2-WorstFit-Unveiling-Hidden-Transformers-in-Windows-ANSI.pdf
- raw.githubusercontent.com /cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-155-01.json
- www.cve.org /CVERecord