CVE-2025-58097 Details
Description
The installation directory of LogStare Collector is configured with incorrect access permissions. A non-administrative user may manipulate files within the installation directory and execute arbitrary code with the administrative privilege.
A vulnerability exists in LogStare Collector for Windows and Linux, all versions through 2.4.1, due to incorrect default permissions in the installation directory. This flaw allows non-administrative users to manipulate files within the directory and execute arbitrary code with administrative privileges.
Users are advised to update LogStare Collector to version 2.4.2 for both Windows and Linux. Instructions for verifying the current version and updating the software are available on the LogStare KnowledgeStare website.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Nov 21, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://jvn.jp/en/jp/JVN77560819/ | [email protected] | Third Party Advisory |
| https://www.logstare.com/vulnerability/2025-001/ | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-276 | Incorrect Default Permissions | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| secuavail logstare collector | < 2.4.2 |
CPE
Remediation
| |
| linux linux kernel | All versions |
CPE
Remediation
| |
| microsoft windows | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Dec 5, 2025 | Initial Analysis | [email protected] |
| Nov 21, 2025 | New CVE Received | [email protected] |