Externally Controlled Reference to a Resource in Another Sphere in Cyber Protect Cloud Agent - CVE-2025-48963

 

Externally Controlled Reference to a Resource in Another Sphere in Cyber Protect Cloud Agent - CVE-2025-48963

Published: October 1, 2026


Vulnerability identifier: #VU153063
CSH Severity: Low
CVSS v4: 7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-48963
CWE-ID: CWE-610
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to improper soft link handling, which leads to security restrictions bypass and privilege escalation.


Affected software

Cyber Protect Cloud Agent

How to mitigate CVE-2025-48963

Install updates from vendor's website.

Cyber Protect Cloud Agent - update to C25.06

External References

Related Security Bulletins