Incorrect Default Permissions vulnerability in AIRBUS PSS TETRA Connectivity Server on Windows Server OS allows Privilege Abuse.


An attacker may execute arbitrary code with SYSTEM privileges if a user is tricked or directed to place a crafted file into the vulnerable directory.

This issue affects TETRA connectivity Server: 7.0.


Vulnerability fix is available and delivered to impacted customers.

Project Subscriptions

No data.

Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 03 Apr 2026 07:45:00 +0000

Type Values Removed Values Added
Description Incorrect Default Permissions vulnerability in AIRBUS PSS TETRA Connectivity Server on Windows Server OS allows Privilege Abuse. An attacker may execute arbitrary code with SYSTEM privileges if a user is tricked or directed to place a crafted file into the vulnerable directory. This issue affects TETRA connectivity Server: 7.0. Vulnerability fix is available and delivered to impacted customers.
Title Local privilege escalation in Windows Server OS through installed Tetra Connectivity Server (TCS)
Weaknesses CWE-276
References
Metrics cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 5.6, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:U'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: airbus

Published:

Updated: 2026-04-03T12:16:42.627Z

Reserved: 2025-07-02T14:50:55.096Z

Link: CVE-2025-7024

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-04-03T08:16:17.290

Modified: 2026-04-03T08:16:17.290

Link: CVE-2025-7024

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses