Incorrect default permissions in LogStare Collector for Linux and LogStare Collector for Windows - CVE-2025-58097

 

Incorrect default permissions in LogStare Collector for Linux and LogStare Collector for Windows - CVE-2025-58097

Published: November 21, 2025


Vulnerability identifier: #VU118655
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-58097
CWE-ID: CWE-276
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to execute arbitrary code on the system.

The vulnerability exists due to incorrect default permissions for files and folders that are set by the application. A local user can manipulate files within the installation directory of the product and execute arbitrary code on the target system.


Affected software

LogStare Collector for Linux
LogStare Collector for Windows

How to mitigate CVE-2025-58097

Install updates from vendor's website.

LogStare Collector for Linux - update to 2.4.2
LogStare Collector for Windows - update to 2.4.2

External References

Related Security Bulletins