Input validation error in SAPCAR - CVE-2025-43001

 

Input validation error in SAPCAR - CVE-2025-43001

Published: August 12, 2025


Vulnerability identifier: #VU113821
CSH Severity: Low
CVSS v4: 7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-43001
CWE-ID: CWE-20
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to insufficient validation of user-supplied input when handling archives. A local user can trick the victim into opening a specially crafted SAR archive and override the permissions of the current and parent directories of the user or process extracting the archive, leading to privilege escalation


Affected software

SAPCAR

How to mitigate CVE-2025-43001

Install updates from vendor's website.


External References

Related Security Bulletins