VDB

CVE-2025-6241

CVE-2025-6241 PUBLISHED CVSS 4.400000095367432 MEDIUM

LsiAgent.exe, a component of SysTrack from Lakeside Software, attempts to load several DLL files which are not present in the default installation. If a user-writable directory is present in the SYSTEM PATH environment variable, the user can write a malicious DLL to that directory with arbitrary code. This malicious DLL is executed in the context of NT AUTHORITY\SYSTEM upon service start or restart, due to the Windows default dynamic-link library search order, resulting in local elevation of privileges.

EPSS 0.07% · 22.1th percentile

Risk Scores

CVSS 3.1
4.400000095367432
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
EPSS Score
0.07%
22.1th percentile

Affected Products

VendorProductVersions
Lakeside SoftwareSysTrack10.05.0027

Timeline

  • Jul 27, 2025 EPSS Score
  • Jul 27, 2025 CVE Published
  • Jul 28, 2025 PoC Published
  • Aug 5, 2025 EPSS Score
  • Aug 14, 2025 EPSS Score
  • Aug 23, 2025 EPSS Score
  • Aug 31, 2025 EPSS Score
  • Sep 9, 2025 EPSS Score
  • Sep 18, 2025 EPSS Score
  • Sep 27, 2025 EPSS Score
  • Oct 6, 2025 EPSS Score
  • Oct 15, 2025 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›