CVE-2020-25245
3Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackepss 0.3%
exploitation probability
0.3%top 72% of all CVEs
observed exploitation
nono source reports it
A vulnerability has been identified in DIGSI 4 (All versions < V4.94 SP1 HF 1). Several folders in the %PATH% are writeable by normal users. As these folders are included in the search for dlls, an attacker could place dlls there with code executed by SYSTEM.
Affected products
Siemens · DIGSI 4