CVE-2025-64699 Details
Description
An incorrect NULL DACL issue exists in SevenCs ORCA G2 2.0.1.35 (EC2007 Kernel v5.22). The regService process, which runs with SYSTEM privileges, applies a Security Descriptor to a device object with no explicitly configured DACL. This condition could allow an attacker to perform unauthorized raw disk operations, which could lead to system disruption (DoS) and exposure of sensitive data, and may facilitate local privilege escalation.
A vulnerability exists in SevenCs ORCA G2 version 2.0.1.35, specifically within the EC2007 Kernel v5.22. The issue arises from the regService process, which operates with SYSTEM privileges, applying a Security Descriptor to a device object without an explicitly configured Discretionary Access Control List (DACL). This NULL DACL state could enable an attacker to conduct unauthorized raw disk operations, potentially leading to system disruption, exposure of sensitive data, and local privilege escalation.
To address this vulnerability, it is advised not to apply permissive ACLs to core device objects like '\\.\C:' unless absolutely necessary. If modifications are required, a least-privilege DACL should be applied, ensuring that the final descriptor does not result in a NULL DACL state or grant broad access. After making changes, the security descriptor should be validated programmatically and regression tests should be added.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jan 2, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://gist.github.com/GunP4ng/42b19ee99e94c315173b74a9fb26c2b9 | [email protected] | ExploitThird Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-732 | Incorrect Permission Assignment for Critical Resource | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| sevencs ec2007 kernel | 5.22 |
CPE
Remediation
| |
| sevencs orca g2 | 2.0.1.35 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 23, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jan 14, 2026 | Initial Analysis | [email protected] |
| Jan 2, 2026 | CVE Modified | CISA-ADP |
| Dec 31, 2025 | New CVE Received | [email protected] |