CVE-2025-5031

LOW

Ackites KillWxapkg <= 2.4.1 - Uncontrolled Resource Consumption in wxapkg File Decompression Handler

Title source: llm
STIX 2.1

Description

A vulnerability was found in Ackites KillWxapkg up to 2.4.1. It has been rated as problematic. This issue affects some unknown processing of the component wxapkg File Decompression Handler. The manipulation leads to resource consumption. The attack may be initiated remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used.

References (5)

Core 5
Core References
Permissions Required, VDB Entry vdb-entry
https://vuldb.com/?id.309851
Permissions Required, VDB Entry signature permissions-required
https://vuldb.com/?ctiid.309851
Permissions Required, VDB Entry third-party-advisory
https://vuldb.com/?submit.580524
Issue Tracking issue-tracking
https://github.com/Ackites/KillWxapkg/issues/86

Scores

CVSS v3 3.1
EPSS 0.0036
EPSS Percentile 27.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-400 CWE-404
Status published
Products (3)
Ackites/KillWxapkg 0Go
Ackites/KillWxapkg 2.4.0
Ackites/KillWxapkg 2.4.1
Published May 21, 2025
Tracked Since Feb 18, 2026