CVE-2025-65116 is a buffer overflow vulnerability affecting multiple Hitachi JP1 and Job Management Partner products on Windows systems, including IT Desktop Management variants, Operations Director, NETM/DM Manager and Client, and Software Distribution tools. The vulnerability impacts numerous versions across different product lines, with affected versions ranging from legacy releases (version 09-00) through recent versions (13-50). The vulnerability presents a medium severity risk with a CVSS score of 5.5, requiring local access with low privileges and no user interaction to trigger. The attack vector is limited to local exploitation, and successful exploitation could result in denial of service through high availability impact, though confidentiality and integrity are not affected. Exploitation status indicates minimal current threat activity, with zero evidence of active exploitation in the wild and an EPSS score of 0.00006, placing this vulnerability well below the threshold for widespread exploitation. The vulnerability has not been designated for the Known Exploited Vulnerabilities catalog and remains classified as inactive on security hotlists, suggesting low community attention and current exploit code availability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 09-50, <= 09-50-03CPE matchmatch criteria | cpe:2.3:a:hitachi:job_management_partner_1\/it_desktop_management-manager:*:*:*:*:*:*:*:* | ||
>= 09-51, <= 09-51-05CPE matchmatch criteria | cpe:2.3:a:hitachi:job_management_partner_1\/it_desktop_management-manager:*:*:*:*:*:*:*:* | ||
>= 10-00, <= 10-00-02CPE matchmatch criteria | cpe:2.3:a:hitachi:job_management_partner_1\/it_desktop_management-manager:*:*:*:*:*:*:*:* | ||
>= 10-01, <= 10-01-05CPE matchmatch criteria | cpe:2.3:a:hitachi:job_management_partner_1\/it_desktop_management-manager:*:*:*:*:*:*:*:* | ||
>= 10-02, <= 10-02-05CPE matchmatch criteria | cpe:2.3:a:hitachi:job_management_partner_1\/it_desktop_management-manager:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.