CyberAlerts is shutting down on June 30th, 2025. Thank you for your support!

CVE-2025-20094: Unprotected Windows messaging channel ('Shatter') issue exists in Defense Platform Home Edition Ver.3.9.51.x and earlier. If an attacker sends a...

8.8 CVSS

Description

Unprotected Windows messaging channel ('Shatter') issue exists in Defense Platform Home Edition Ver.3.9.51.x and earlier. If an attacker sends a specially crafted message to the specific process of the Windows system where the product is running, arbitrary code may be executed with SYSTEM privilege.

Classification

CVE ID: CVE-2025-20094

CVSS Base Severity: HIGH

CVSS Base Score: 8.8

CVSS Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Affected Products

Vendor: Humming Heads Inc.

Product: Defense Platform Home Edition

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.04% (probability of being exploited)

EPSS Percentile: 11.87% (scored less or equal to compared to others)

EPSS Date: 2025-03-07 (when was this score calculated)

References

https://www.hummingheads.co.jp/dep/storelist/
https://jvn.jp/en/jp/JVN66673020/

Timeline