CVE-2025-14599

MEDIUM

Altera Quartus Prime <24.1 - Buffer Overflow

Title source: llm
STIX 2.1

Description

Uncontrolled Search Path Element vulnerability in Altera Quartus Prime Standard Installer (SFX) on Windows, Altera Quartus Prime Lite  Installer (SFX) on Windows allows Search Order Hijacking.This issue affects Quartus Prime Standard: from 23.1 through 24.1; Quartus Prime Lite: from 23.1 through 24.1.

Scores

CVSS v3 6.7
EPSS 0.0002
EPSS Percentile 4.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-427
Status published
Products (1)
intel/quartus_prime 23.1 - 25.1 (2 CPE variants)
Published Jan 07, 2026
Tracked Since Feb 18, 2026