WinMatrix3 developed by Simopro Technology has an Insecure Deserialization vulnerability, allowing unauthenticated remote attackers to execute arbitrary code on the server by sending maliciously crafted serialized contents.
History

Tue, 22 Jul 2025 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Simopro Technology
Simopro Technology winmatrix3
Vendors & Products Simopro Technology
Simopro Technology winmatrix3

Mon, 21 Jul 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 21 Jul 2025 06:15:00 +0000

Type Values Removed Values Added
Description WinMatrix3 developed by Simopro Technology has an Insecure Deserialization vulnerability, allowing unauthenticated remote attackers to execute arbitrary code on the server by sending maliciously crafted serialized contents.
Title Simopro Technology|WinMatrix3 - Insecure Deserialization
Weaknesses CWE-502
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: twcert

Published: 2025-07-21T05:57:51.661Z

Updated: 2025-07-21T18:23:55.612Z

Reserved: 2025-07-21T01:58:23.151Z

Link: CVE-2025-7916

cve-icon Vulnrichment

Updated: 2025-07-21T18:23:16.675Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-07-21T06:15:27.817

Modified: 2025-07-22T13:06:07.260

Link: CVE-2025-7916

cve-icon Redhat

No data.