CVE-2025-63945
7.4Tencent · iOA app
A local privilege escalation vulnerability exists in the Tencent iOA app for Windows, allowing unprivileged users to execute programs with elevated privileges via a race condition.
Executive summary
A local privilege escalation vulnerability in the Tencent iOA app allows attackers to execute code with elevated system privileges, posing a significant risk to endpoint security.
Vulnerability
This is a privilege escalation flaw caused by a race condition. The vulnerability allows an unauthenticated local user to bypass security controls and execute arbitrary code with elevated privileges on affected Windows systems.
Business impact
The ability for a local user to gain elevated privileges represents a complete compromise of the affected endpoint. This could lead to unauthorized data access, the installation of malicious software, or further lateral movement within the network. Given the CVSS score of 7.4, this vulnerability is classified as High severity due to the potential for total impact on system confidentiality, integrity, and availability.
Remediation
Immediate Action: Organizations should restrict local user access to the affected Windows devices and monitor for suspicious process execution patterns until a formal patch is released by the vendor.
Proactive Monitoring: Security teams should audit endpoint logs for unexpected privilege changes or the execution of unauthorized binaries originating from the Tencent iOA installation directory.
Compensating Controls: Implement strict application allowlisting to prevent the execution of untrusted programs, which can limit the impact of an escalated session.
Exploitation status
Public Exploit Available: Yes, a public proof of concept is available via the GitHub repositories linked in the vendor references.
Analyst recommendation
The vulnerability presents a serious risk to internal systems where Tencent iOA is deployed. Administrators must prioritize the containment of affected endpoints and monitor for vendor updates. Once a patch is provided, it should be deployed across the enterprise immediately to close the privilege escalation vector.