CVE-2026-37454: Infoleak
Published Jun 25, 2026
·Updated
Insecure Permissions vulnerability in MSI NBFoundation Service v.2.0.2506.1201 allows a remote attacker to obtain sensitive information via the 3DES-ECB encryption
Affected Software
2 affected components
MSI NBFoundation Service=2.0.2506.1201
MSI Center<2.0.70.0
Event History
Jun 25, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·08:17 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-37454?
CVE-2026-37454 has a high severity rating of 7.5 on the CVSS scale.
2
How do I fix CVE-2026-37454?
To fix CVE-2026-37454, update the MSI NBFoundation Service to the latest version that addresses this vulnerability.
3
What type of vulnerability is CVE-2026-37454?
CVE-2026-37454 is classified as an insecure permissions vulnerability.
4
What information can be compromised due to CVE-2026-37454?
CVE-2026-37454 allows remote attackers to obtain sensitive information through weak 3DES-ECB encryption.
5
What software is affected by CVE-2026-37454?
CVE-2026-37454 affects MSI NBFoundation Service version 2.0.2506.1201.