CVE-2025-8884: CWE-639 Authorization Bypass Through User-Controlled Key in VHS Electronic Software Ltd. Co. ACE Center
Authorization Bypass Through User-Controlled Key vulnerability in VHS Electronic Software Ltd. Co. ACE Center allows Privilege Abuse, Exploitation of Trusted Identifiers. This issue affects ACE Center: from 3.10.100.1768 before 3.10.161.2255.
AI Analysis
Technical Summary
This vulnerability (CVE-2025-8884) in ACE Center allows an attacker with low privileges and local access to bypass authorization controls by manipulating user-controlled keys. This leads to privilege abuse and exploitation of trusted identifiers, potentially granting unauthorized access to sensitive functions or data. The issue affects versions from 3.10.100.1768 before 3.10.161.2255. The CVSS vector indicates the attack requires low complexity, low privileges, no user interaction, and impacts confidentiality but not integrity or availability.
Potential Impact
Successful exploitation can result in unauthorized access to sensitive information due to confidentiality impact, without affecting system integrity or availability. The medium severity score reflects the limited attack vector (local access with low privileges) and the absence of known exploits in the wild.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Since no official patch or workaround information is provided, users should monitor vendor communications for updates and avoid using affected versions if possible.
CVE-2025-8884: CWE-639 Authorization Bypass Through User-Controlled Key in VHS Electronic Software Ltd. Co. ACE Center
Description
Authorization Bypass Through User-Controlled Key vulnerability in VHS Electronic Software Ltd. Co. ACE Center allows Privilege Abuse, Exploitation of Trusted Identifiers. This issue affects ACE Center: from 3.10.100.1768 before 3.10.161.2255.
CVSS v3.1
Score 5.5medium
Affected software
pkg:github/vhs-electronic-software-ltd-co/ACE-CenterRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability (CVE-2025-8884) in ACE Center allows an attacker with low privileges and local access to bypass authorization controls by manipulating user-controlled keys. This leads to privilege abuse and exploitation of trusted identifiers, potentially granting unauthorized access to sensitive functions or data. The issue affects versions from 3.10.100.1768 before 3.10.161.2255. The CVSS vector indicates the attack requires low complexity, low privileges, no user interaction, and impacts confidentiality but not integrity or availability.
Potential Impact
Successful exploitation can result in unauthorized access to sensitive information due to confidentiality impact, without affecting system integrity or availability. The medium severity score reflects the limited attack vector (local access with low privileges) and the absence of known exploits in the wild.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Since no official patch or workaround information is provided, users should monitor vendor communications for updates and avoid using affected versions if possible.
Technical Details
- Data Version
- 5.1
- Assigner Short Name
- TR-CERT
- Date Reserved
- 2025-08-12T07:31:09.354Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 68f64b0d50505a0863bf2f73
Added to database: 10/20/2025, 14:45:33 UTC
Last enriched: 06/05/2026, 20:13:32 UTC
Last updated: 09/10/2026, 19:36:52 UTC
Views: 205
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.