CVE-2025-61871 describes a privilege escalation vulnerability in BUFFALO INC.'s NAS Navigator2 Windows version, stemming from an unquoted file path in a registered Windows service. This allows a local attacker with write permissions to the system drive's root directory to execute arbitrary code with SYSTEM privileges. While the CVSS score is 6.7 (MEDIUM), indicating high impact on confidentiality, integrity, and availability, it requires high privileges (PR:H) for exploitation. Currently, there is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| BUFFALO INC. | NAS Navigator2 (Windows Version Only) | prior to Ver.3.12.0CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.