CVE-2026-25264
8.8Qualcomm · Snapdragon
Qualcomm Snapdragon contains a privilege escalation vulnerability due to a weak configuration during the package extraction process, allowing for uncontrolled search path element exploitation.
Executive summary
A privilege escalation vulnerability in Qualcomm Snapdragon on Windows may allow local attackers to gain elevated system privileges.
Vulnerability
This vulnerability, categorized as CWE-427 (Uncontrolled Search Path Element), occurs during the package extraction process. An attacker with low-level local access can exploit this weak configuration to execute arbitrary code with higher privileges.
Business impact
The vulnerability carries a CVSS score of 8.8, indicating high severity. Successful exploitation allows a local user to escalate privileges, potentially leading to full system compromise, unauthorized data access, and the ability to disable security controls. This poses a significant risk to organizational endpoints running the affected Snapdragon software.
Remediation
Immediate Action: Review the official Qualcomm security bulletin for the release of a patched version and apply updates to affected Windows systems immediately.
Proactive Monitoring: Monitor system logs for unauthorized attempts to modify or execute files within the application's installation directories.
Compensating Controls: Restrict local user permissions to prevent unauthorized access to sensitive directories used by the package extraction process.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Given the potential for total system compromise, organizations should prioritize patching affected Snapdragon versions. Administrators must monitor the Qualcomm security portal for the availability of a specific fix and deploy it across all vulnerable Windows endpoints as soon as it is released.
More Qualcomm CVEs all →
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Analyst report updated
- Published in the daily brief high section