CVE Explorer
CVE-2025-63602
A vulnerability was discovered in Awesome Miner thru 11.2.4 that allows arbitrary read and write to kernel memory and MSRs (such as LSTAR) as an unprivileged user. This is due to the implementation of an insecure version of WinRing0 (1.2.0.5, renamed to IntelliBreeze.Maintenance.Service.sys) that lacks a properly secured DACL, allowing unprivileged users to interact with the driver and, as a result, the kernel. This can result in local privilege escalation, information disclosure, denial of serv
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
1
Preserved source conflicts
No provider value was silently selected as the winner.
cwe · 2 assertions
{"description":"n/a","lang":"en","type":"text"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:69f34b94955096510eb30d886454e76cfcb19c35bece3352f84d5bc3b036d4e9 · sha256:af11aa514c0c52bc… · /containers/cna/problemTypes/0/descriptions/0
{"cweId":"CWE-126","description":"CWE-126 Buffer Over-read","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:69f34b94955096510eb30d886454e76cfcb19c35bece3352f84d5bc3b036d4e9 · sha256:af11aa514c0c52bc… · /containers/adp/0/problemTypes/0/descriptions/0
Affected products and versions
1 source assertion{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:69f34b94955096510eb30d886454e76cfcb19c35bece3352f84d5bc3b036d4e9 · sha256:af11aa514c0c52bc… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"LOW","baseScore":7.3,"baseSeverity":"HIGH","confidentialityImpact":"LOW","integrityImpact":"LOW","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:69f34b94955096510eb30d886454e76cfcb19c35bece3352f84d5bc3b036d4e9 · sha256:af11aa514c0c52bc… · /containers/adp/0/metrics/0/cvssV3_1
CWE assertions
2 source assertions{"description":"n/a","lang":"en","type":"text"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:69f34b94955096510eb30d886454e76cfcb19c35bece3352f84d5bc3b036d4e9 · sha256:af11aa514c0c52bc… · /containers/cna/problemTypes/0/descriptions/0
{"cweId":"CWE-126","description":"CWE-126 Buffer Over-read","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:69f34b94955096510eb30d886454e76cfcb19c35bece3352f84d5bc3b036d4e9 · sha256:af11aa514c0c52bc… · /containers/adp/0/problemTypes/0/descriptions/0
Source references
2 source assertions{"url":"https://dreadsec.co/p/cve-2025-63602-hijacking-system-calls-with-a-popular-crypto-miner.html"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:69f34b94955096510eb30d886454e76cfcb19c35bece3352f84d5bc3b036d4e9 · sha256:af11aa514c0c52bc… · /containers/cna/references/1
{"url":"https://www.awesomeminer.com/download"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:69f34b94955096510eb30d886454e76cfcb19c35bece3352f84d5bc3b036d4e9 · sha256:af11aa514c0c52bc… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.