{"id":"CVE-2025-64701","title":"QND Premium/Advance/Standard Ver.11.0.9i and prior contains a privilege escalation vulnerability, which may allow a user who can log in to a Windows system with the affected product to gain administrator privileges","summary":"QND Premium/Advance/Standard Ver.11.0.9i and prior contains a privilege escalation vulnerability, which may allow a user who can log in to a Windows system with the affected product to gain administrator privileges. As a result, sensitiv…","severity":"high","cvss":7.8,"cvssVector":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-268"],"published":"2025-12-11","updated":"2026-10-08","sourceUpdated":"2026-10-08T10:10:00.227","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-64701","references":[{"url":"https://jvn.jp/jp/JVN40102375/","label":"vultures@jpcert.or.jp"},{"url":"https://www.qualitysoft.com/product/qnd_vulnerabilities_2025/","label":"vultures@jpcert.or.jp"}],"tags":["nvd"],"epss":0.00122,"epssPercentile":0.01737,"ingestedAt":"2026-10-08T10:28:24.626Z","slug":"CVE-2025-64701","body":"## Overview\n\nQND Premium/Advance/Standard Ver.11.0.9i and prior contains a privilege escalation vulnerability, which may allow a user who can log in to a Windows system with the affected product to gain administrator privileges. As a result, sensitive information may be accessed or altered, and arbitrary actions may be performed.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":43,"depthScoreParts":{"impact":42.9,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}