VulnerabilityDeferred
CVE-2025-12507
Due to the way Windows searches the executable for the BCS service, malicious programs can be executed.
HIGH 8.8EPSS 0.13%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.13%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The service Bizerba Communication Server (BCS) has an unquoted service path. Due to the way Windows searches the executable for the BCS service, malicious programs can be executed.
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
- EPSS
- 0.13% probability · 3th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-428
- Source
- 0beee27a-7d8c-424f-8e46-ac453fa147e6
References
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.