CVE-2025-10475 describes a denial-of-service vulnerability in SpyShelter versions up to 15.4.0.1015, specifically within an unknown function of the SpyShelter.sys library's IOCTL Handler. This flaw can be triggered locally by an authenticated attacker, leading to system instability. With a CVSS score of 5.5 (Medium), the vulnerability is relatively easy to exploit (low attack complexity, no user interaction required) but only impacts availability. While a public exploit exists, there is no evidence of active exploitation, and community discussion and media coverage are minimal. Organizations using affected SpyShelter versions should upgrade to 15.4.0.1028 immediately to mitigate this risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| N/A | SpyShelter | 15.4.0.1015CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.