Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2025-65199 Details

Description

A command injection vulnerability exists in Windscribe for Linux Desktop App that allows a local user who is a member of the windscribe group to execute arbitrary commands as root via the 'adapterName' parameter of the 'changeMTU' function. Fixed in Windscribe v2.18.3-alpha and v2.18.8.

Metrics

CVSS 3.x Severity and Vector Strings:

CNA: Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian GovernmentCVSS-B:7.8 HIGHVector:CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

URLSource(s)Tag(s)
https://github.com/Windscribe/Desktop-App Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian GovernmentProduct
https://github.com/Windscribe/Desktop-App/compare/v2.18.2...v2.18.3?diff=unified&w#diff-57e27ab201a1a612609087b839e03bf87a5a063ffcc3f465a6245469bc102754 Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian GovernmentPatch
https://github.com/Windscribe/Desktop-App/compare/v2.18.2...v2.18.3?diff=unified&w#diff-cfc5df17057ed92112ae70a42c81c57c79f434429210ff881fb0771cf8e39b4c Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian GovernmentPatch
https://hackingbydoing.wixsite.com/hackingbydoing/post/windscribe-vpn-local-privilege-escalation Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian GovernmentExploitPress/Media CoverageThird Party Advisory
https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-343-01.json Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian GovernmentThird Party Advisory

see all 6 references

Weakness Enumeration

CWE-IDCWE NameSource
CWE-78Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government

Affected Products

ProductVersions
windscribe windscribe
>= 2.10.1, <= 2.17.10
2.18.1 alpha
2.18.3
2.18.5

CPE

  • cpe:2.3:a:windscribe:windscribe:*:*:*:*:*:linux:*:*
  • cpe:2.3:a:windscribe:windscribe:2.18.1:alpha:*:*:*:linux:*:*
  • cpe:2.3:a:windscribe:windscribe:2.18.3:*:*:*:*:linux:*:*
  • cpe:2.3:a:windscribe:windscribe:2.18.5:*:*:*:*:linux:*:*

Remediation

  • No remediation found in references.

Change History

5 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2025-65199
NVD Published Date:
Dec 10, 2025
NVD Last Modified:
Sep 25, 2026
Source:
Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government
CVE-2025-65199 Details - Not Deferred