CVE-2025-14605: Quartus Prime Pro Edition Advisory
Uncontrolled Search Path Element vulnerability in Altera Quartus Prime Pro on Windows (System Console modules) allows Search Order Hijacking.This issue affects Quartus Prime Pro: from 17.0 through 25.1.1.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-14605?
CVE-2025-14605 has a high severity due to its potential for Search Order Hijacking, which can lead to unauthorized code execution.
How do I fix CVE-2025-14605?
To fix CVE-2025-14605, update Altera Quartus Prime Pro to version 25.1.2 or later, where the vulnerability is addressed.
What versions of Altera Quartus Prime Pro are affected by CVE-2025-14605?
CVE-2025-14605 affects Altera Quartus Prime Pro versions from 17.0 to 25.1.1.
What are the potential impacts of CVE-2025-14605?
If exploited, CVE-2025-14605 can allow attackers to execute arbitrary code by hijacking the search path for executable files.
Is there a workaround for CVE-2025-14605 if I cannot update?
A potential workaround for CVE-2025-14605 is to monitor and limit access to the directories included in the executable search path to mitigate exploitation.