Externally Controlled Reference to a Resource in Another Sphere in Cyber Protect Cloud Agent - CVE-2025-48963
Published: October 1, 2026
Vulnerability identifier: #VU153063
CSH Severity: Low
CVSS v4: 7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-48963
CWE-ID: CWE-610
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to improper soft link handling, which leads to security restrictions bypass and privilege escalation.
Affected software
Cyber Protect Cloud Agent
How to mitigate CVE-2025-48963
Install updates from vendor's website.
Cyber Protect Cloud Agent - update to C25.06