CVE-2025-13665 Details
Description
The System Console Utility for Windows is vulnerable to a DLL planting vulnerability
A DLL planting vulnerability has been identified in the System Console Utility for Windows, part of the Altera Quartus Prime Standard Edition Design Software. This vulnerability arises when the Quartus Prime Programmer and Tools package is installed independently, rather than as part of a complete Quartus Prime Standard Edition installation. The issue does not affect the Linux version of the software.
Users can upgrade to Quartus Prime Standard Edition version 24.1 or later. Alternatively, if version 24.1 or later is not available, the full Quartus Standard version can be installed to use the System Console Utility. For users of the original Design Space Explorer, the obsolete qcmd.bat file can be deleted to mitigate the vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Dec 12, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.altera.com/security/security-advisory/asa-0002 | Altera | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-427 | Uncontrolled Search Path Element | Altera |
Affected Products
| Product | Versions |
|---|---|
| intel quartus prime | < 24.1 |
CPE
Remediation
| |
| microsoft windows | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | Altera |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jan 12, 2026 | Initial Analysis | [email protected] |
| Dec 12, 2025 | New CVE Received | Altera |