CVE-2025-63421

7.8

Filosoft · Comerc.32 Commercial Invoicing

A local arbitrary code execution vulnerability exists in Filosoft Comerc.32 Commercial Invoicing version 16.0.0.3, triggered via the comeinst.exe file.

Executive summary

A local code execution vulnerability in Filosoft Comerc.32 Commercial Invoicing poses a significant risk to system integrity and security.

Vulnerability

This is a local execution flaw within the comeinst.exe file, which allows an authenticated local attacker to execute arbitrary code on the host system.

Business impact

The ability for a local attacker to execute arbitrary code with the privileges of the application presents a high risk of total system compromise, including unauthorized data access and potential persistence. With a CVSS score of 7.8, this vulnerability is classified as High severity, necessitating prompt attention to prevent unauthorized escalation or system-wide disruption.

Remediation

Immediate Action: Contact the vendor, Filosoft, to obtain the necessary security updates or configuration changes to secure the comeinst.exe executable.

Proactive Monitoring: Review system access logs for unauthorized execution of binaries and monitor for unusual process creation originating from the installation directory of the invoicing software.

Compensating Controls: Implement strict file-system permissions to restrict access to the comeinst.exe file to authorized users only, effectively limiting the attack surface for local malicious actors.

Exploitation status

Public Exploit Available: Yes — a published proof-of-concept exists, as documented in the technical write-up referenced by the CVE record.

Analyst recommendation

Given the availability of a proof-of-concept and the high potential for impact, organizations should prioritize the identification of affected systems and coordinate with Filosoft for a resolution. Restricting local access to the vulnerable executable is a necessary interim step while a formal patch is applied to mitigate the risk of arbitrary code execution.

Sources