CVE-2025-0425 Details
Description
Via the GUI of the "bestinformed Infoclient", a low-privileged user is by default able to change the server address of the "bestinformed Server" to which this client connects. This is dangerous as the "bestinformed Infoclient" runs with elevated permissions ("nt authority\system"). By changing the server address to a malicious server, or a script simulating a server, the user is able to escalate his privileges by abusing certain features of the "bestinformed Web" server. Those features include: * Pushing of malicious update packages * Arbitrary Registry Read as "nt authority\system" An attacker is able to escalate his privileges to "nt authority\system" on the Windows client running the "bestinformed Infoclient". This attack is not possible if a custom configuration ("Infoclient.ini") containing the flags "ShowOnTaskbar=false" or "DisabledItems=stPort,stAddress" is deployed.
A vulnerability in Cordaware Bestinformed Infoclient versions prior to 6.3.8.1 allows low-privileged users to change the server address of the Bestinformed Server that the client connects to. This is problematic because the Infoclient operates with elevated permissions as 'nt authority\system'. By redirecting the server address to a malicious server or a script that mimics a server, users can exploit certain features of the Bestinformed Web server to escalate privileges to 'nt authority\system' on the Windows client. Exploitation can involve pushing malicious update packages or performing arbitrary registry reads as 'nt authority\system'. However, this vulnerability can be mitigated by deploying a custom configuration file that disables the relevant GUI options or by using the Infoclient quick configuration to lock the address and port fields.
Users can upgrade to Cordaware Bestinformed Infoclient version 6.3.8.1 or later, where this vulnerability has been addressed. Instructions for updating can be found on the Cordaware website.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Feb 18, 2025CISA-ADP
Assessed Feb 18, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.cordaware.com/changelog/en/version-6_3_8_1.html | [email protected] | Release NotesVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-15 | External Control of System or Configuration Setting | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Cordaware bestinformed Infoclient | < 6.3.7.0 |
CPE
Remediation
| |
| Cordaware bestinformed Server | All versions |
CPE
Remediation
| |
| Cordaware bestinformed Web | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Feb 18, 2025 | New CVE Received | [email protected] |
Volerion