CVE-2024-52925: Code Injection
Published Feb 26, 2025
·Updated
In OPSWAT MetaDefender Kiosk before 4.7.0, arbitrary code execution can be performed by an attacker via the MD Kiosk Unlock Device feature for software encrypted USB drives.
Affected Software
1 affected component
OPSWAT MetaDefender KIOSK<4.7.0
Event History
Feb 26, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-52925?
CVE-2024-52925 is classified as a critical vulnerability due to its potential for arbitrary code execution.
2
How do I fix CVE-2024-52925?
To remediate CVE-2024-52925, upgrade OPSWAT MetaDefender Kiosk to version 4.7.0 or later.
3
What type of systems are affected by CVE-2024-52925?
CVE-2024-52925 affects OPSWAT MetaDefender Kiosk versions earlier than 4.7.0.
4
What could an attacker achieve using CVE-2024-52925?
An attacker could execute arbitrary code on the system through the MD Kiosk Unlock Device feature for software encrypted USB drives.
5
Is there a workaround for CVE-2024-52925?
There are no known workarounds for CVE-2024-52925; upgrading to the fixed version is the recommended action.