CVE-2025-14605 Details
Description
Uncontrolled Search Path Element vulnerability in Altera Quartus Prime Pro on Windows (System Console modules) allows Search Order Hijacking.This issue affects Quartus Prime Pro: from 17.0 through 25.1.1.
A vulnerability allowing search order hijacking has been identified in Altera Quartus Prime Pro Edition for Windows, specifically within the System Console utility. This vulnerability, categorized as an uncontrolled search path element issue, affects versions 17.0 through 25.1.1. The vulnerability arises from a current working directory planting attack, which could potentially lead to unauthorized privilege escalation.
Users are advised to upgrade to Quartus Prime Pro Edition 25.1.1 or later. For those using Quartus Prime Pro Edition Programmer and Tools, version 25.1.1 or later should be used.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jan 7, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.altera.com/security/security-advisory/asa-0004 | Altera | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-427 | Uncontrolled Search Path Element | Altera |
Affected Products
| Product | Versions |
|---|---|
| intel quartus prime | >= 17.0, < 25.1.1 |
CPE
Remediation
| |
| microsoft windows | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | Altera |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jan 12, 2026 | Initial Analysis | [email protected] |
| Jan 7, 2026 | New CVE Received | Altera |