CVE-2025-61303 Details
Description
Hatching Triage Sandbox Windows 10 build 2004 (2025-08-14) and Windows 10 LTSC 2021(2025-08-14) contains a vulnerability in its Windows behavioral analysis engine that allows a submitted malware sample to evade detection and cause denial-of-analysis. The vulnerability is triggered when a sample recursively spawns a large number of child processes, generating high log volume and exhausting system resources. As a result, key malicious behavior, including PowerShell execution and reverse shell activity, may not be recorded or reported, misleading analysts and compromising the integrity and availability of sandboxed analysis results.
A denial-of-analysis vulnerability has been identified in the RecordedFuture Triage Sandbox, specifically in Windows 10 build 2004 and Windows 10 LTSC 2021. This vulnerability allows malware samples to evade detection by the behavioral analysis engine. It is triggered when a sample recursively creates a large number of child processes, which generates excessive log volume and depletes system resources. Consequently, critical malicious activities, such as PowerShell execution and reverse shell communications, may go unrecorded, misleading analysts and undermining the reliability of sandbox analysis results.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Oct 20, 2025CISA-ADP
Assessed Oct 21, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/eGkritsis/CVE-2025-61303 | [email protected] | ExploitTechnical Analysis |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-400 | Uncontrolled Resource Consumption | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| RecordedFuture Triage | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Oct 21, 2025 | CVE Modified | CISA-ADP |
| Oct 20, 2025 | New CVE Received | [email protected] |
Volerion