VDB
CVE-2025-6241
CVE-2025-6241
PUBLISHED
CVSS 4.400000095367432 MEDIUM
LsiAgent.exe, a component of SysTrack from Lakeside Software, attempts to load several DLL files which are not present in the default installation. If a user-writable directory is present in the SYSTEM PATH environment variable, the user can write a malicious DLL to that directory with arbitrary code. This malicious DLL is executed in the context of NT AUTHORITY\SYSTEM upon service start or restart, due to the Windows default dynamic-link library search order, resulting in local elevation of privileges.
EPSS 0.07% · 22.1th percentile
Risk Scores
CVSS 3.1
4.400000095367432
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
EPSS Score
0.07%
22.1th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Lakeside Software | SysTrack | 10.05.0027 |
Timeline
- Jul 27, 2025 EPSS Score
- Jul 27, 2025 CVE Published
- Jul 28, 2025 PoC Published
- Aug 5, 2025 EPSS Score
- Aug 14, 2025 EPSS Score
- Aug 23, 2025 EPSS Score
- Aug 31, 2025 EPSS Score
- Sep 9, 2025 EPSS Score
- Sep 18, 2025 EPSS Score
- Sep 27, 2025 EPSS Score
- Oct 6, 2025 EPSS Score
- Oct 15, 2025 EPSS Score