---
id: CVE-2025-64695
title: >-
  Uncontrolled search path element issue exists in the installer of LogStare
  Collector (for Windows)
summary: >-
  Uncontrolled search path element issue exists in the installer of LogStare
  Collector (for Windows). If exploited, arbitrary code may be executed with the
  privilege of the user invoking the installer.
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'
cwe:
  - CWE-427
vendor: secuavail
product: logstare_collector
affected:
  - logstare_collector < 2.4.2
patched:
  - logstare_collector 2.4.2
published: '2025-11-21'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T21:10:00.200'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-64695'
references:
  - url: 'https://jvn.jp/en/jp/JVN77560819/'
    label: vultures@jpcert.or.jp
  - url: 'https://www.logstare.com/vulnerability/2025-001/'
    label: vultures@jpcert.or.jp
tags:
  - nvd
epss: 0.0015
epssPercentile: 0.03618
ingestedAt: '2026-10-07T21:54:15.070Z'
---

## Overview

Uncontrolled search path element issue exists in the installer of LogStare Collector (for Windows). If exploited, arbitrary code may be executed with the privilege of the user invoking the installer.

## Affected

- `logstare_collector < 2.4.2`

## Remediation

Upgrade past the affected range:

- `logstare_collector 2.4.2`
