Incorrect default permissions issue exists in Security Point (Windows) of MaLion prior to Ver.5.3.4. If this vulnerability is exploited, an arbitrary file could be placed in the specific folder by a user who can log in to the system where the product's Windows client is installed. If the file is a specially crafted DLL file, arbitrary code could be executed with SYSTEM privilege.
History

Wed, 26 Nov 2025 11:15:00 +0000

Type Values Removed Values Added
First Time appeared Intercom
Intercom malion
Microsoft
Microsoft windows
Vendors & Products Intercom
Intercom malion
Microsoft
Microsoft windows

Tue, 25 Nov 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 25 Nov 2025 07:30:00 +0000

Type Values Removed Values Added
Description Incorrect default permissions issue exists in Security Point (Windows) of MaLion prior to Ver.5.3.4. If this vulnerability is exploited, an arbitrary file could be placed in the specific folder by a user who can log in to the system where the product's Windows client is installed. If the file is a specially crafted DLL file, arbitrary code could be executed with SYSTEM privilege.
Weaknesses CWE-276
References
Metrics cvssV3_0

{'score': 3.3, 'vector': 'CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}

cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: jpcert

Published: 2025-11-25T07:20:38.296Z

Updated: 2025-11-25T14:42:13.300Z

Reserved: 2025-11-18T02:02:14.649Z

Link: CVE-2025-59485

cve-icon Vulnrichment

Updated: 2025-11-25T14:42:09.340Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-11-25T08:15:53.357

Modified: 2025-11-25T22:16:16.690

Link: CVE-2025-59485

cve-icon Redhat

No data.