CVE-2025-56230: High severity Tencent Docs Desktop vulnerability
Published Nov 4, 2025
·Updated
Tencent Docs Desktop 3.9.20 and earlier suffers from Missing SSL Certificate Validation in the update component.
Affected Software
2 affected components
Tencent Docs Desktop<=3.9.20
Tencent Docs<=3.9.20
Event History
Nov 4, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·10:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-56230?
CVE-2025-56230 is classified as a high-severity vulnerability due to its exploitation potential affecting data integrity.
2
How do I fix CVE-2025-56230?
To resolve CVE-2025-56230, upgrade Tencent Docs Desktop to version 3.9.21 or later, which includes the necessary SSL certificate validation improvements.
3
What type of vulnerability is CVE-2025-56230?
CVE-2025-56230 is a missing SSL certificate validation vulnerability within the update component of Tencent Docs Desktop.
4
Which versions of Tencent Docs Desktop are affected by CVE-2025-56230?
CVE-2025-56230 affects Tencent Docs Desktop versions 3.9.20 and earlier.
5
What could happen if CVE-2025-56230 is exploited?
Exploitation of CVE-2025-56230 could allow attackers to perform man-in-the-middle attacks, compromising the integrity and confidentiality of data during updates.