CVE-2025-61156

HIGH

ThreatFire System Monitor <4.7.0.53 - Privilege Escalation

Title source: llm
STIX 2.1

Description

Incorrect access control in the kernel driver of ThreatFire System Monitor v4.7.0.53 allows attackers to escalate privileges and execute arbitrary commands via an insecure IOCTL.

References (3)

Core 3

Scores

CVSS v3 7.8
EPSS 0.0012
EPSS Percentile 2.0%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-284
Status published
Published Oct 29, 2025
Tracked Since Feb 18, 2026