CVE-2025-14599: Quartus® Prime Standard and Quartus® Prime Lite Security Advisory
Uncontrolled Search Path Element vulnerability in Altera Quartus Prime Standard
Installer (SFX)
on Windows, Altera Quartus Prime Lite
Installer (SFX)
on Windows allows Search Order Hijacking.This issue affects Quartus Prime Standard: from 23.1 through 24.1; Quartus Prime Lite: from 23.1 through 24.1.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-14599?
CVE-2025-14599 has a high severity rating due to its potential for search order hijacking.
How do I fix CVE-2025-14599?
To fix CVE-2025-14599, update to the latest version of Altera Quartus Prime that addresses this vulnerability.
What is the impact of CVE-2025-14599 on Altera Quartus Prime Standard and Lite?
The impact of CVE-2025-14599 is primarily that it allows attackers to execute malicious code through a compromised search path.
Which versions of Altera Quartus Prime are affected by CVE-2025-14599?
CVE-2025-14599 affects Altera Quartus Prime Standard from versions 23.1 through 24.1 and Quartus Prime Lite from the same versions.
Can CVE-2025-14599 be exploited remotely?
Yes, CVE-2025-14599 can be exploited remotely if an attacker can introduce a malicious executable into the search path.