CVE-2023-25438

HIGH

Genomedics MilleGP5 5.9.2 - Incorrect Permission Assignment for Critical Resource

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2023-25438. PoCs published by Andrea Intilangelo.

AI-analyzed exploit summary The exploit describes a local privilege escalation vulnerability in MilleGPG5 5.9.2 due to insecure file/folder permissions, allowing unprivileged users to modify critical application files. The writeup details affected paths and permission issues but does not include functional exploit code.

Description

An issue was discovered in Genomedics MilleGP5 5.9.2, allows remote attackers to execute arbitrary code and gain escalated privileges via modifying specific files.

Exploits (1)

exploitdb WRITEUP
by Andrea Intilangelo · textlocalwindows
https://www.exploit-db.com/exploits/51410

The exploit describes a local privilege escalation vulnerability in MilleGPG5 5.9.2 due to insecure file/folder permissions, allowing unprivileged users to modify critical application files. The writeup details affected paths and permission issues but does not include functional exploit code.

Classification
Writeup 90%
Attack Type
Lpe
Complexity
Trivial
Reliability
Reliable
Target: MilleGPG5 5.9.2
No auth needed
Prerequisites: Access to a low-privileged user account on the target system
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (2)

Core 2

Scores

CVSS v3 7.8
EPSS 0.0209
EPSS Percentile 79.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-732
Status published
Products (1)
genomedics/millegpg 5.9.2
Published May 04, 2023
Tracked Since Feb 18, 2026