CVE-2025-15065 Details
Description
Exposure of Sensitive Information to an Unauthorized Actor, Missing Encryption of Sensitive Data, Files or Directories Accessible to External Parties vulnerability in Kings Information & Network Co. KESS Enterprise on Windows allows Privilege Escalation, Modify Existing Service, Modify Shared File.This issue affects KESS Enterprise: before *.25.9.19.exe
A vulnerability in Kings Information & Network Co. KESS Enterprise on Windows, prior to version 25.9.19, allows unauthorized access to sensitive information and data. This issue can be exploited to escalate privileges, modify existing services, and alter shared files. The vulnerability arises from missing encryption of sensitive data, coupled with exposure to external parties.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Dec 29, 2025CISA-ADP
Assessed Dec 29, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.kings.co.kr/solution/01/KESS.jsp?O=10.64&B=Chrome | FSI | ProductVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-200 | Exposure of Sensitive Information to an Unauthorized Actor | FSI |
| CWE-311 | Missing Encryption of Sensitive Data | FSI |
| CWE-552 | Files or Directories Accessible to External Parties | FSI |
Affected Products
| Product | Versions |
|---|---|
| Kings Information & Network Co. KESS Enterprise | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | FSI |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Dec 31, 2025 | CVE Modified | FSI |
| Dec 29, 2025 | New CVE Received | FSI |
Volerion