Out-of-bounds read in ControlVault3 and ControlVault3 Plus - CVE-2025-36463
Published: November 18, 2025
Vulnerability details
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary condition in the ControlVault WBDI Driver Broadcom Storage Adapter functionality within WBIO_USH_ADD_RECORD. A local user can use a specially crafted WinBioControlUnit call, trigger an out-of-bounds read error and cause a denial of service condition on the system.
Affected software
ControlVault3 Plus
How to mitigate CVE-2025-36463
ControlVault3 Plus - update to 6.2.36.47