Skip to content

CVE-2025-57836

The Magician installer creates a temporary folder with weak permissions during installation, allowing a non-admin user to perform DLL hijacking and escalate privileges.

This table summarizes key information about the CVE-2025-57836, including its identifier, title, affected products, versions, severity, reporting date, patched versions, and acknowledgement status.
Category Content
CVE ID CVE-2025-57836
Description The Magician installer creates a temporary folder with weak permissions during installation, allowing a non-admin user to perform DLL hijacking and escalate privileges.
Affected Product 6.3.0-8.3.2
Affected Component Windows Installer
Severity High
Reported Date 2025-08-11
Acknowledgment Sandro Poppi