First published: Tue Apr 01 2025(Updated: )
A vulnerability in the HPE Aruba Networking Virtual Intranet Access (VIA) client could allow malicious users to overwrite arbitrary files as NT AUTHORITY\SYSTEM (root). A successful exploit could allow the creation of a Denial-of-Service (DoS) condition affecting the Microsoft Windows Operating System. This vulnerability does not affect Linux and Android based clients.
Credit: security-alert@hpe.com
Affected Software | Affected Version | How to fix |
---|---|---|
HPE Aruba Networking Virtual Intranet Access | ||
Microsoft Windows Operating System |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-25041 is considered a critical vulnerability due to its potential to allow unauthorized file overwrites and create a Denial-of-Service condition.
To address CVE-2025-25041, update the HPE Aruba Networking Virtual Intranet Access (VIA) client to the latest version provided by HPE.
CVE-2025-25041 affects users of the HPE Aruba Networking Virtual Intranet Access (VIA) client and the Microsoft Windows Operating System.
CVE-2025-25041 can allow malicious users to overwrite files as NT AUTHORITY\SYSTEM, potentially leading to Denial-of-Service attacks.
Currently, it is recommended to apply the latest patches or updates as a primary measure, rather than relying on workarounds for CVE-2025-25041.