CVE-2025-58742 Details
Description
Insufficiently Protected Credentials, Improper Restriction of Communication Channel to Intended Endpoints vulnerability in the Connection Settings dialog in Milner ImageDirector Capture on Windows allows Adversary in the Middle (AiTM) by modifying the 'Server' field to redirect client authentication.This issue affects ImageDirector Capture: from 7.0.9 before 7.6.3.25808.
A vulnerability in the Connection Settings dialog of Milner ImageDirector Capture on Windows has been identified, allowing for an Adversary in the Middle (AiTM) attack. This issue arises from insufficiently protected credentials and improper restriction of communication channels to intended endpoints. By modifying the 'Server' field, it is possible to redirect client authentication. The vulnerability affects Milner ImageDirector Capture versions from 7.0.9 prior to 7.6.3.25808, with earlier versions potentially also being impacted.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jan 21, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://sra.io/advisories | Security Risk Advisors | Third Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-522 | Insufficiently Protected Credentials | [email protected] |
| CWE-522 | Insufficiently Protected Credentials | Security Risk Advisors |
| CWE-923 | Improper Restriction of Communication Channel to Intended Endpoints | Security Risk Advisors |
Affected Products
| Product | Versions |
|---|---|
| milner imagedirector capture | >= 7.0.9, < 7.6.3.25808 |
CPE
Remediation
| |
| microsoft windows | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | Security Risk Advisors |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Feb 10, 2026 | Initial Analysis | [email protected] |
| Jan 20, 2026 | New CVE Received | Security Risk Advisors |