Incorrect default permissions in LogStare Collector for Linux and LogStare Collector for Windows - CVE-2025-58097
Published: November 21, 2025
Vulnerability identifier: #VU118655
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-58097
CWE-ID: CWE-276
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to execute arbitrary code on the system.
The vulnerability exists due to incorrect default permissions for files and folders that are set by the application. A local user can manipulate files within the installation directory of the product and execute arbitrary code on the target system.
Affected software
LogStare Collector for Linux
LogStare Collector for Windows
LogStare Collector for Windows
How to mitigate CVE-2025-58097
Install updates from vendor's website.
LogStare Collector for Linux - update to 2.4.2
LogStare Collector for Windows - update to 2.4.2
LogStare Collector for Windows - update to 2.4.2