CVE-2025-3773: Medium severity System Information Reporter SIR vulnerability
A sensitive information exposure vulnerability in System Information Reporter (SIR) 1.0.3 and prior allows an authenticated non-admin local user to extract sensitive information stored in a registry backup folder.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-3773?
The severity of CVE-2025-3773 is classified as medium due to its potential for sensitive information exposure.
How do I fix CVE-2025-3773?
To fix CVE-2025-3773, update to version 1.0.4 or later of the System Information Reporter software.
Who is affected by CVE-2025-3773?
Authenticated non-admin local users of System Information Reporter versions 1.0.3 and prior are affected by CVE-2025-3773.
What kind of data is exposed in CVE-2025-3773?
CVE-2025-3773 allows for the extraction of sensitive information stored in a registry backup folder.
Can I mitigate CVE-2025-3773 without upgrading?
Mitigation for CVE-2025-3773 may be limited, but restricting access to the registry backup folder can reduce risk.