SEPTEMBER 8, 2026
Live Feed
Back to database
Case File

CVE-2025-59866

LOW · CVSS 3.3 EPSS 0.07%

Source: NVD + CISA KEV + EPSS · Published 2026-07-17 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

The HCL DFMPro, DFXAnalytics, and DFXServer installers are vulnerable due to insecure file permissions, allowing non-administrative users to overwrite executable files with malicious binaries. This privilege escalation could lead to unauthorized execution of arbitrary code, potentially compromising system integrity. Organizations using these products should prioritize remediation to mitigate the risk of exploitation.

CVE
CVE-2025-59866
Severity
LOW
CVSS
3.3
EPSS
0.07%

Original NVD Description

The HCL DFMPro, DFXAnalytics and DFXServer installers are affected by ‘Insecure file permissions Leading to Privilege Escalation’ vulnerability, which enables any logged-in non-administrative user to overwrite or replace the executable file with a malicious binary.