CVE-2025-5180

Published May 26, 2025

Last updated a month ago

Overview

Description
A vulnerability, which was classified as critical, has been found in Wondershare Filmora 14.5.16. Affected by this issue is some unknown functionality in the library CRYPTBASE.dll of the file NFWCHK.exe of the component Installer. The manipulation leads to uncontrolled search path. Attacking locally is a requirement. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Source
cna@vuldb.com
NVD status
Analyzed

Risk scores

CVSS 4.0

Type
Secondary
Base score
7.3
Impact score
-
Exploitability score
-
Vector string
CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity
HIGH

CVSS 3.1

Type
Primary
Base score
7.3
Impact score
5.9
Exploitability score
1.3
Vector string
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Severity
HIGH

CVSS 2.0

Type
Secondary
Base score
6
Impact score
10
Exploitability score
1.5
Vector string
AV:L/AC:H/Au:S/C:C/I:C/A:C

Weaknesses

cna@vuldb.com
CWE-426
nvd@nist.gov
CWE-427

Social media

Hype score
Not currently trending
  1. CVE-2025-5180 (CVSS:7.3, HIGH) is Undergoing Analysis. A vulnerability, which was classified as critical, has been found in Wondershare Filmora 14.5.16. Affected by this issue..https://t.co/LozuCRmEOR #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    @cracbot

    31 May 2025

    4 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. CVE-2025-5180 (CVSS:7.3, HIGH) is Undergoing Analysis. A vulnerability, which was classified as critical, has been found in Wondershare Filmora 14.5.16. Affected by this issue..https://t.co/LozuCRmEOR #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    @cracbot

    30 May 2025

    4 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. CVE-2025-5180 (CVSS:7.3, HIGH) is Awaiting Analysis. A vulnerability, which was classified as critical, has been found in Wondershare Filmora 14.5.16. Affected by this issue..https://t.co/LozuCRmEOR #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    @cracbot

    29 May 2025

    10 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. 🚨 CVE-2025-5180 🔴 HIGH (7.3) 🏢 Wondershare - Filmora 🏗️ 14.5.16 🔗 https://t.co/7e3fIm2Apt 🔗 https://t.co/RtvCZJJMP8 🔗 https://t.co/IsCM0PrniO 🔗 https://t.co/udWFlpogUM #CyberCron #VulnAlert #InfoSec https://t.co/Jg69HrkNnC

    @cybercronai

    26 May 2025

    33 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. CVE-2025-5180 A vulnerability, which was classified as critical, has been found in Wondershare Filmora 14.5.16. Affected by this issue is some unknown functionality in the library CR… https://t.co/FD623NCUM3

    @CVEnew

    26 May 2025

    441 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations