CVE-2025-10941 Details
Description
A vulnerability was determined in Topaz SERVCore Teller 2.14.0-RC2/2.14.1. Affected by this issue is some unknown functionality of the file SERVCoreTeller_2.0.40D.msi of the component Installer. Executing manipulation can lead to permission issues. The attack needs to be launched locally. You should upgrade the affected component. The vendor explains, that "this vulnerability was detected at the beginning of 2025, it was remediated because the latest published version of the installer no longer uses "nssm," which is responsible for this vulnerability".
A local privilege escalation vulnerability exists in Topaz SERVCore Teller versions 2.14.0-RC2 and 2.14.1. The issue arises from improper permission management in the installation directory of the service binary. This flaw allows unprivileged users to replace the service binary with a malicious executable, which is then executed with SYSTEM privileges upon reboot.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 25, 2025CISA-ADP
Assessed Sep 25, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://raw.githubusercontent.com/securityadvisories/Security-Advisories/refs/heads/main/Advisories/Blaze%20Information%20Security%20-%20Local%20Privilege%20Escalation%20via%20Insecure%20Directory%20Permissions%20in%20SERVCore%20Teller%20Installer.txt | [email protected] | AdvisoryRemedy |
| https://vuldb.com/?ctiid.325811 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/?id.325811 | [email protected] | AdvisoryPartial Content |
| https://vuldb.com/?submit.651434 | [email protected] | Technical Description |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-266 | Incorrect Privilege Assignment | [email protected] |
| CWE-275 | Permission Issues | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Topaz SERVCore Teller | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Sep 30, 2025 | CVE Modified | [email protected] |
| Sep 25, 2025 | New CVE Received | [email protected] |
Volerion