CVE-2025-1700
7.0Motorola · Software Fix (Rescue and Smart Assistant)
A DLL hijacking vulnerability in the Motorola Software Fix installer allows a local attacker to escalate privileges during software installation.
Executive summary
A DLL hijacking vulnerability in the Motorola Software Fix installer poses a significant risk of local privilege escalation, necessitating an immediate update to the latest version.
Vulnerability
This vulnerability is an uncontrolled search path element (CWE-427) where the installer improperly handles DLL loading. An attacker with local access can place a malicious DLL in the search path to achieve privilege escalation during the installation process.
Business impact
The ability for a local attacker to escalate privileges represents a critical security failure, as it allows unauthorized users to gain administrative control over the affected system. This could lead to full system compromise, data theft, or the installation of persistent malware. With a CVSS score of 7.0, this high-severity flaw requires swift remediation to prevent local threats from becoming catastrophic security incidents.
Remediation
Immediate Action: Update the Motorola Software Fix (Rescue and Smart Assistant) application to version 7.3.4.13 or later as provided in the vendor security advisory.
Proactive Monitoring: Monitor system logs for unauthorized installation activities or the creation of unexpected files within the software installation directory.
Compensating Controls: Restrict local user permissions and monitor for unusual process execution patterns that deviate from standard software deployment behavior.
Exploitation status
Public Exploit Available: exploit_available (false)
Analyst recommendation
Given the potential for complete system compromise, IT administrators must prioritize updating the Motorola Software Fix software across all managed environments. Verify the installation of version 7.3.4.13 to ensure the vulnerable search path element is properly addressed, effectively mitigating the risk of local privilege escalation.
Sources
Originally found and disclosed by Motorola/Lenovo thanks Shaurya and Sahil Shah for reporting this issue., per the CVE Program record.