CVE-2025-61161: High severity Evope Collector vulnerability
DLL hijacking vulnerability in Evope Collector 1.1.6.9.0 and related components load the wtsapi32.dll library from an uncontrolled search path (C:\ProgramData\Evope). This allows local unprivileged attackers to execute arbitrary code or escalate privileges to SYSTEM by placing a crafted DLL in that location. The vulnerable component is Evope.Service.exe, which runs with SYSTEM privileges and automatically loads the DLL on startup or reboot.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-61161?
CVE-2025-61161 is a high-severity DLL hijacking vulnerability that allows execution of arbitrary code.
How do I fix CVE-2025-61161?
To fix CVE-2025-61161, ensure that the application loads the wtsapi32.dll library from a secure and controlled path.
Who is affected by CVE-2025-61161?
CVE-2025-61161 affects users of Evope Collector version 1.1.6.9.0 and potentially related components.
What can an attacker do with CVE-2025-61161?
An attacker can execute arbitrary code or escalate privileges to SYSTEM by exploiting CVE-2025-61161.
How can I mitigate CVE-2025-61161?
Mitigation for CVE-2025-61161 includes applying software updates and configuring proper file permissions for the affected directories.