CVE-2025-63421
7.8Filosoft · Comerc.32 Commercial Invoicing
A local arbitrary code execution vulnerability exists in Filosoft Comerc.32 Commercial Invoicing version 16.0.0.3, triggered via the comeinst.exe file.
Executive summary
A local code execution vulnerability in Filosoft Comerc.32 Commercial Invoicing poses a significant risk to system integrity and security.
Vulnerability
This is a local execution flaw within the comeinst.exe file, which allows an authenticated local attacker to execute arbitrary code on the host system.
Business impact
The ability for a local attacker to execute arbitrary code with the privileges of the application presents a high risk of total system compromise, including unauthorized data access and potential persistence. With a CVSS score of 7.8, this vulnerability is classified as High severity, necessitating prompt attention to prevent unauthorized escalation or system-wide disruption.
Remediation
Immediate Action: Contact the vendor, Filosoft, to obtain the necessary security updates or configuration changes to secure the comeinst.exe executable.
Proactive Monitoring: Review system access logs for unauthorized execution of binaries and monitor for unusual process creation originating from the installation directory of the invoicing software.
Compensating Controls: Implement strict file-system permissions to restrict access to the comeinst.exe file to authorized users only, effectively limiting the attack surface for local malicious actors.
Exploitation status
Public Exploit Available: Yes — a published proof-of-concept exists, as documented in the technical write-up referenced by the CVE record.
Analyst recommendation
Given the availability of a proof-of-concept and the high potential for impact, organizations should prioritize the identification of affected systems and coordinate with Filosoft for a resolution. Restricting local access to the vulnerable executable is a necessary interim step while a formal patch is applied to mitigate the risk of arbitrary code execution.