CVE-2025-1161
7.1NomySoft · Nomysem
Nomysem contains an incorrect use of privileged APIs that allows an authenticated user to perform privilege escalation.
Executive summary
A vulnerability in NomySoft Nomysem allows authenticated attackers to perform privilege escalation, posing a significant risk to system integrity.
Vulnerability
This flaw stems from the improper use of privileged APIs, classified as CWE-648, which allows a low-privileged authenticated user to gain unauthorized administrative access. The attack vector requires network access and specific user interaction, as indicated by the CVSS vector.
Business impact
Successful exploitation of this vulnerability permits an attacker to escalate privileges, potentially leading to full system compromise. With a CVSS score of 7.1, this is a high-severity issue that could result in unauthorized access to sensitive data, system reconfiguration, or the total loss of service integrity.
Remediation
Immediate Action: Contact NomySoft support or monitor the official vendor security portal for the release of a security patch, as no specific fixed version is currently documented.
Proactive Monitoring: Review system and application access logs for unusual administrative activities or unexpected account privilege changes.
Compensating Controls: Implement strict access controls and minimize the number of users with elevated permissions to reduce the potential impact of an escalation attempt.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Organizations utilizing Nomysem should immediately identify all instances of the software within their environment. Given the potential for privilege escalation, administrators must prioritize the application of security updates once the vendor releases a fix. Until a patch is available, ensure that all relevant system logs are being monitored to detect any signs of unauthorized privilege modifications.
Sources
Originally found and disclosed by Mustafa Anıl YILDIRIM, per the CVE Program record.