CVE-2025-14625: Quartus® Prime Standard and Quartus® Prime Lite Security Advisory

Published Jan 6, 2026
·
Updated

Uncontrolled Search Path Element vulnerability in Altera Quartus Prime Standard on Windows (Nios II Command Shell modules), Altera Quartus Prime Lite on Windows (Nios II Command Shell modules) allows Search Order Hijacking.This issue affects Quartus Prime Standard: from 19.1 through 24.1; Quartus Prime Lite: from 19.1 through 24.1.

Affected Software

5 affected components
Altera Quartus Prime Standard>=undefined
Altera Quartus Prime Lite>=undefined
All of the following
Any of the following
Intel Quartus Prime>=19.1<25.1
Intel Quartus Prime>=19.1<25.1
Microsoft Windows

Event History

Jan 6, 2026
CVE Published
via MITRE·09:42 PM
Data Sourced
via MITRE·09:42 PM
DescriptionSeverityWeakness
Jan 7, 2026
Data Sourced
via NVD·12:16 PM
DescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2025-14625?

CVE-2025-14625 is classified as a high-severity vulnerability, as it allows search order hijacking.

2

How do I fix CVE-2025-14625?

To fix CVE-2025-14625, ensure that your installation of Altera Quartus Prime Standard or Quartus Prime Lite is updated to the latest version provided by Altera.

3

What impact does CVE-2025-14625 have on my system?

CVE-2025-14625 can potentially allow an attacker to execute arbitrary code through search order hijacking, compromising system integrity.

4

Which versions of Altera Quartus are affected by CVE-2025-14625?

CVE-2025-14625 affects all versions of Altera Quartus Prime Standard and Quartus Prime Lite prior to their latest security updates.

5

Is CVE-2025-14625 exploitable remotely?

CVE-2025-14625 is exploitable locally, requiring the attacker to have access to the affected system.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203