CVE-2025-57392

HIGH

Benimpos - Incorrect Permission Assignment

Title source: rule

Description

BenimPOS Masaustu 3.0.x is affected by insecure file permissions. The application installation directory grants Everyone and BUILTIN\Users groups FILE_ALL_ACCESS, allowing local users to replace or modify .exe and .dll files. This may lead to privilege escalation or arbitrary code execution upon launch by another user or elevated context.

Exploits (1)

nomisec WORKING POC
by meisterlos · poc
https://github.com/meisterlos/CVE-2025-57392

Scores

CVSS v3 7.8
EPSS 0.0002
EPSS Percentile 6.3%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-732
Status published
Products (1)
benimpos/benimpos 3.0
Published Sep 10, 2025
Tracked Since Feb 18, 2026