OVERVIEW CVE-2025-14821 is a privilege escalation and man-in-the-middle vulnerability affecting libssh on Windows systems. The flaw stems from an insecure default configuration where the library automatically loads SSH configuration files from the C:\etc directory, a location that unprivileged local users can create and modify. This allows attackers to manipulate SSH connections and trusted host information. SEVERITY The vulnerability carries a CVSS score of 7.8 (HIGH) with a local attack vector requiring low complexity and low privilege access. No user interaction is required for exploitation. The impact is severe, affecting all three security pillars: confidentiality (ability to intercept communications), integrity (capacity to modify connections and host trust data), and availability of SSH communications. The attack enables security downgrades and man-in-the-middle attacks against SSH sessions. EXPLOITATION STATUS There is currently no evidence of active exploitation. The EPSS score of 0.00011 indicates minimal real-world exploitation likelihood relative to other CVEs, and the vulnerability is not listed on the Known Exploited Vulnerabilities (KEV) catalog. No public exploit code is currently known to be available. The vulnerability maintains an inactive status on threat intelligence hot lists, suggesting limited community or threat actor attention at present.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.12.0CPE matchmatch criteria | cpe:2.3:a:libssh:libssh:*:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:redhat:hardened_images:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.