CVE-2025-25041: Arbitrary File Overwrite in HPE Aruba Networking Virtual Intranet Access (VIA) Microsoft Windows Client
A vulnerability in the HPE Aruba Networking Virtual Intranet Access (VIA) client could allow malicious users to overwrite arbitrary files as NT AUTHORITY\SYSTEM (root). A successful exploit could allow the creation of a Denial-of-Service (DoS) condition affecting the Microsoft Windows Operating System. This vulnerability does not affect Linux and Android based clients.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-25041?
CVE-2025-25041 is considered a critical vulnerability due to its potential to allow unauthorized file overwrites and create a Denial-of-Service condition.
How do I fix CVE-2025-25041?
To address CVE-2025-25041, update the HPE Aruba Networking Virtual Intranet Access (VIA) client to the latest version provided by HPE.
Who is affected by CVE-2025-25041?
CVE-2025-25041 affects users of the HPE Aruba Networking Virtual Intranet Access (VIA) client and the Microsoft Windows Operating System.
What type of attacks can CVE-2025-25041 facilitate?
CVE-2025-25041 can allow malicious users to overwrite files as NT AUTHORITY\SYSTEM, potentially leading to Denial-of-Service attacks.
Is there a workaround for CVE-2025-25041?
Currently, it is recommended to apply the latest patches or updates as a primary measure, rather than relying on workarounds for CVE-2025-25041.