CVE-2025-22894

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
06/02/2025
Last modified:
04/02/2026

Description

Unprotected Windows messaging channel ('Shatter') issue exists in Defense Platform Home Edition Ver.3.9.51.x and earlier. If an attacker sends a specially crafted message to the specific process of the Windows system where the product is running, arbitrary files in the system may be altered. As a result, an arbitrary DLL may be executed with SYSTEM privilege.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:hummingheads:defense_platform:*:*:*:*:home:*:*:* 3.9.51.0 (including)