CVE-2025-22894HIGH 8.8EPSS p3.1%
CVE-2025-22894CVE-2025-22894
Description
Unprotected Windows messaging channel ('Shatter') issue exists in Defense Platform Home Edition Ver.3.9.51.x and earlier. If an attacker sends a specially crafted message to the specific process of the Windows system where the product is running, arbitrary files in the system may be altered. As a result, an arbitrary DLL may be executed with SYSTEM privilege.
Scoring
| CVSS 3.1 | 8.8 (HIGH) |
| Vector | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
| EPSS | 0.13% probability of exploitation · percentile 3.1% · 2026-06-19T12:03:05Z |
| Published | 2025-02-06 |
| Last modified | 2026-02-04 |
Underlying weaknesses· 1
References
1
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Unprotected Windows Messaging Channel ('Shatter')cwe-422 | 0% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.