CVE-2025-14596 Details
Description
Uncontrolled Search Path Element vulnerability in Altera Quartus Prime Pro Installer (SFX) on Windows allows Search Order Hijacking.This issue affects Quartus Prime Pro: from 24.1 through 24.3.1.
A search order hijacking vulnerability has been identified in the Altera Quartus Prime Pro Installer (SFX) for Windows, affecting versions 24.1 through 24.3.1. This vulnerability arises from an uncontrolled search path element, allowing for a binary planting attack. The issue is not present in the Linux version of the installer.
Users are advised to upgrade to the Quartus 25.1 Pro Edition installer or later. For those using older versions of Quartus Prime Pro, downloading the individual installation files directly from the Altera download page will avoid this issue, as these files are not affected by the vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jan 6, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.altera.com/security/security-advisory/asa-0004 | Altera | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-427 | Uncontrolled Search Path Element | Altera |
Affected Products
| Product | Versions |
|---|---|
| intel quartus prime | >= 24.1, < 25.1 |
CPE
Remediation
| |
| microsoft windows | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | Altera |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jan 12, 2026 | Initial Analysis | [email protected] |
| Jan 7, 2026 | New CVE Received | Altera |