CVE-2025-59866: Low severity HCL DFMPro vulnerability
The HCL DFMPro, DFXAnalytics and DFXServer installers are affected by ‘Insecure file permissions Leading to Privilege Escalation’ vulnerability, which enables any logged-in non-administrative user to overwrite or replace the executable file with a malicious binary.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-59866?
The severity of CVE-2025-59866 is classified as low with a score of 3.3.
What is the risk associated with CVE-2025-59866?
CVE-2025-59866 presents a risk level of 23, indicating a low severity privilege escalation vulnerability.
How do I fix CVE-2025-59866?
To fix CVE-2025-59866, ensure that proper file permissions are set to prevent non-administrative users from overwriting executable files.
What products are affected by CVE-2025-59866?
CVE-2025-59866 affects HCL DFMPro, HCL DFXAnalytics, and HCL DFXServer.
What type of vulnerability is CVE-2025-59866?
CVE-2025-59866 is an 'Insecure file permissions' vulnerability that can lead to privilege escalation.