Description
NAVER MYBOX Explorer for Windows before 3.0.8.133 allows a local attacker to escalate privileges to NT AUTHORITY\SYSTEM by executing arbitrary files due to improper privilege checks.
Problem types
CWE-266 Incorrect Privilege Assignment
Product status
3.0.8.133
Credits
Minwoo Jeong of KAIST Hacking Lab (@p1nkjelly)
References
cve.naver.com/detail/cve-2025-58323.html (NAVER Security Advisory)