CVE-2025-14599: Quartus® Prime Standard and Quartus® Prime Lite Security Advisory

Published Jan 6, 2026
·
Updated

Uncontrolled Search Path Element vulnerability in Altera Quartus Prime Standard

Installer (SFX)

on Windows, Altera Quartus Prime Lite

Installer (SFX)

on Windows allows Search Order Hijacking.This issue affects Quartus Prime Standard: from 23.1 through 24.1; Quartus Prime Lite: from 23.1 through 24.1.

Affected Software

5 affected components
Altera Quartus Prime Standard>=undefined
Altera Quartus Prime Lite>=undefined
All of the following
Any of the following
Intel Quartus Prime>=23.1<25.1
Intel Quartus Prime>=23.1<25.1
Microsoft Windows

Event History

Jan 6, 2026
CVE Published
via MITRE·09:30 PM
Data Sourced
via MITRE·09:30 PM
DescriptionSeverityWeakness
Jan 7, 2026
Data Sourced
via NVD·02:02 AM
DescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2025-14599?

CVE-2025-14599 has a high severity rating due to its potential for search order hijacking.

2

How do I fix CVE-2025-14599?

To fix CVE-2025-14599, update to the latest version of Altera Quartus Prime that addresses this vulnerability.

3

What is the impact of CVE-2025-14599 on Altera Quartus Prime Standard and Lite?

The impact of CVE-2025-14599 is primarily that it allows attackers to execute malicious code through a compromised search path.

4

Which versions of Altera Quartus Prime are affected by CVE-2025-14599?

CVE-2025-14599 affects Altera Quartus Prime Standard from versions 23.1 through 24.1 and Quartus Prime Lite from the same versions.

5

Can CVE-2025-14599 be exploited remotely?

Yes, CVE-2025-14599 can be exploited remotely if an attacker can introduce a malicious executable into the search path.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203