PT-2025-26951 · Trellix · System Information Reporter

·

CVE-2025-3771

·

Published

2025-06-26

·

Updated

2026-02-11

CVSS v4.0

7.2

High

VectorAV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:H/VA:H/SC:L/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions: System Information Reporter versions 1.0.3 and prior
Description: The issue allows a local user to manipulate the location of registry backup files by creating a junction symlink, potentially overwriting system files. This can be achieved by adding a malicious entry to the registry or via policy, which may cause a system crash. An authenticated non-admin local user can exploit this to access files they would not normally have permission to access.
Recommendations: For System Information Reporter versions 1.0.3 and prior, consider restricting access to the registry under the Trellix SIR registry folder to minimize the risk of exploitation. As a temporary workaround, avoid using junction symbolic links in the System Information Reporter until a patch is available. Restrict access to system files that the user would not normally have permission to access to prevent potential overwrites.

Fix

Link Following

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-3771

Affected Products

System Information Reporter