CVE-2025-2425: TOCTOU race condition vulnerability in ESET products on Windows
Published Jul 18, 2025
·Updated
Time-of-check to time-of-use race condition vulnerability potentially allowed an attacker to use the installed ESET security software to clear the content of an arbitrary file on the file system.
Affected Software
1 affected component
ESET ESET Security Software
Event History
Jul 18, 2025
CVE Published
via MITRE·09:20 AM
Data Sourced
via MITRE·09:20 AM
DescriptionWeakness
Data Sourced
via NVD·10:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-2425?
CVE-2025-2425 is considered a high severity vulnerability due to its potential impact on file system integrity.
2
How do I fix CVE-2025-2425?
To fix CVE-2025-2425, ensure that you update your ESET Security Software to the latest version provided by ESET.
3
Can CVE-2025-2425 allow unauthorized file access?
Yes, CVE-2025-2425 can allow an attacker to clear the content of an arbitrary file on the system, leading to unauthorized access.
4
Which ESET products are affected by CVE-2025-2425?
CVE-2025-2425 affects ESET Security Software on Windows platforms.
5
What type of vulnerability is CVE-2025-2425?
CVE-2025-2425 is categorized as a time-of-check to time-of-use (TOCTOU) race condition vulnerability.