Out-of-bounds write in ControlVault3 and ControlVault3 Plus - CVE-2025-36462
Published: November 18, 2025
Vulnerability details
The vulnerability allows a local user to compromise vulnerable system.
The vulnerability exists due to a boundary error when processing untrusted input in the ControlVault WBDI Driver Broadcom Storage Adapter functionality within WBIO_USH_CREATE_CHALLENGE. A local user can use a specially crafted WinBioControlUnit call, trigger an out-of-bounds write and execute arbitrary code on the target system.
Affected software
ControlVault3 Plus
How to mitigate CVE-2025-36462
ControlVault3 Plus - update to 6.2.36.47