PT-2026-85065 · Exterro · Ftk Imager

CVE-2026-82525

·

Published

2026-09-03

·

Updated

2026-09-03

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Exterro FTK Imager versions prior to 8.3
Description An XML external entity (XXE) injection exists where attackers can read arbitrary files from the host filesystem. This is achieved by embedding malicious external entity references and attacker-controlled XSLT stylesheets within a Report.xml file located inside a UFDR ZIP evidence item. When an examiner previews a crafted UFDR archive, the XML parser resolves file:// external entity references and executes msxsl:script within the external stylesheet. This process allows the exfiltration of resolved file contents to an attacker-controlled endpoint through a generated image URL.
Recommendations Update Exterro FTK Imager to version 8.3 or later.

Fix

XXE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-82525

Affected Products

Ftk Imager