CVE-2025-64699

HIGH

SevenCs ORCA G2 2.0.1.35 (EC2007 Kernel v5.22) - Incorrect NULL DACL in regService Device Object

Title source: llm
STIX 2.1

Description

An incorrect NULL DACL issue exists in SevenCs ORCA G2 2.0.1.35 (EC2007 Kernel v5.22). The regService process, which runs with SYSTEM privileges, applies a Security Descriptor to a device object with no explicitly configured DACL. This condition could allow an attacker to perform unauthorized raw disk operations, which could lead to system disruption (DoS) and exposure of sensitive data, and may facilitate local privilege escalation.

References (1)

Core 1
Core References

Scores

CVSS v3 7.8
EPSS 0.0013
EPSS Percentile 2.9%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-732
Status published
Products (2)
sevencs/ec2007_kernel 5.22
sevencs/orca_g2 2.0.1.35
Published Dec 31, 2025
Tracked Since Feb 18, 2026