We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2025-41255

Cyberduck and Mountain Duck - Improper Certificate Store Handling



Description

Cyberduck and Mountain Duck improperly handle TLS certificate pinning for untrusted certificates (e.g., self-signed), unnecessarily installing it to the Windows Certificate Store of the current user without any restrictions. This issue affects Cyberduck through 9.1.6 and Mountain Duck through 4.17.5.

Reserved 2025-04-16 | Published 2025-06-25 | Updated 2025-06-25 | Assigner sba-research


HIGH: 8.0CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:N

Problem types

CWE-266: Incorrect Privilege Assignment

Product status

Default status
unaffected

Any version
affected

Default status
unaffected

Any version
affected

Credits

Thomas Kostal finder

Andreas Boll finder

References

github.com/...1_Cyberduck_Mountain_Duck_Certificate_Handling third-party-advisory

github.com/...erduck/security/advisories/GHSA-vjjc-grpp-m655 vendor-advisory

cve.org (CVE-2025-41255)

nvd.nist.gov (CVE-2025-41255)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2025-41255

Support options

Helpdesk Chat, Email, Knowledgebase