Milner's vulnerability profile concentrates in ImageDirector Capture, a niche capture and imaging product where disclosures center on credential and cryptographic key hardening issues, including insufficiently protected credentials, default credentials, hard-coded secrets, and improper communication-channel restrictions. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Milner over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-58744HIGH Use of Default Credentials, Hard-coded Credentials vulnerability in C2SGlobalSettings.dll in
Milner ImageDirector Capture on Windows allows decryption of document archive files | Jan 20, 2026 | 7.5 | 28 | NO | NO |
CVE-2025-58741HIGH Insufficiently Protected Credentials vulnerability in the Credential Field of Milner ImageDirector Capture allows retrieval of credential material and enables database access.This | Jan 20, 2026 | 7.5 | 28 | NO | NO |
CVE-2025-58743HIGH Use of a Broken or Risky Cryptographic Algorithm (DES) vulnerability
in the Password class in C2SConnections.dll in Milner ImageDirector Capture on Windows allows Encryption Brut | Jan 20, 2026 | 7.5 | 24 | NO | NO |
CVE-2025-58742MEDIUM Insufficiently Protected Credentials, Improper Restriction of Communication Channel to Intended Endpoints vulnerability in the Connection Settings dialog in Milner ImageDirector Ca | Jan 20, 2026 | 5.9 | 24 | NO | NO |
CVE-2025-58740MEDIUM The use of a hard-coded encryption key in calls to the Password function in C2SGlobalSettings.dll in Milner ImageDirector Capture on Windows allows a local attacker to decrypt data | Jan 20, 2026 | 5.5 | 23 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Milner.
Media articles that mention a CVE ID that affects a product developed by Milner — matched by CVE ID, not by vendor name.