CVE-2025-10941 is a high-severity local permission issue affecting Topaz SERVCore Teller versions 2.14.0-RC2 and 2.14.1, specifically within the installer component (SERVCoreTeller_2.0.40D.msi). This vulnerability, stemming from the use of "nssm" in older installers, allows a local attacker to achieve high confidentiality, integrity, and availability impacts. The vendor has already remediated this issue in later versions by removing the problematic "nssm" component. Currently, there is no public exploit code available, nor is there any evidence of active exploitation or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Topaz | SERVCore Teller | 2.14.0-RC2, 2.14.1CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.