---
id: CVE-2025-64701
title: >-
  QND Premium/Advance/Standard Ver.11.0.9i and prior contains a privilege
  escalation vulnerability, which may allow a user who can log in to a Windows
  system with the affected product to gain administrator privileges
summary: >-
  QND Premium/Advance/Standard Ver.11.0.9i and prior contains a privilege
  escalation vulnerability, which may allow a user who can log in to a Windows
  system with the affected product to gain administrator privileges. As a
  result, sensitiv…
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-268
published: '2025-12-11'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T10:10:00.227'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-64701'
references:
  - url: 'https://jvn.jp/jp/JVN40102375/'
    label: vultures@jpcert.or.jp
  - url: 'https://www.qualitysoft.com/product/qnd_vulnerabilities_2025/'
    label: vultures@jpcert.or.jp
tags:
  - nvd
epss: 0.00122
epssPercentile: 0.01737
ingestedAt: '2026-10-08T10:28:24.626Z'
---

## Overview

QND Premium/Advance/Standard Ver.11.0.9i and prior contains a privilege escalation vulnerability, which may allow a user who can log in to a Windows system with the affected product to gain administrator privileges. As a result, sensitive information may be accessed or altered, and arbitrary actions may be performed.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
