CVE-2018-25043

MEDIUM

uTorrent - Weak Authentication via PRNG

Title source: llm
STIX 2.1

Description

A vulnerability classified as critical was found in uTorrent. This vulnerability affects unknown code of the component PRNG. The manipulation leads to weak authentication. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. It is recommended to upgrade the affected component.

References (3)

Core 3
Core References
Exploit, Issue Tracking, Mailing List, Third Party Advisory x_refsource_misc
https://bugs.chromium.org/p/project-zero/issues/detail?id=1524
Third Party Advisory x_refsource_misc
http://www.math.sci.hiroshima-u.ac.jp/~m-mat/MT/efaq.html
Exploit, Permissions Required, Third Party Advisory, VDB Entry x_refsource_misc
https://vuldb.com/?id.113806

Scores

CVSS v3 5.0
EPSS 0.0108
EPSS Percentile 60.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-287
Status published
Products (1)
bittorrent/utorrent
Published Jun 17, 2022
Tracked Since Feb 18, 2026