The following table lists the changes that have been made to the
CVE-2025-34109 vulnerability over time.
Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.
-
CVE Modified
by [email protected]Jul. 15, 2025
Action Type Old Value New Value Added Reference https://www.vulncheck.com/advisories/panda-security-psevents-insecure-dll-loading-privilege-escalation Removed Reference https://vulncheck/advisories/panda-security-psevents-insecure-dll-loading-privilege-escalation -
New CVE Received
by [email protected]Jul. 15, 2025
Action Type Old Value New Value Added Description PSEvents.exe in multiple Panda Security products runs hourly with SYSTEM privileges and loads DLL files from a user-writable directory without proper validation. An attacker with low-privileged access who can write DLL files to the monitored directory can achieve arbitrary code execution with SYSTEM privileges. Affected products include Panda Global Protection 2016, Panda Antivirus Pro 2016, Panda Small Business Protection, and Panda Internet Security 2016 (all versions up to 16.1.2). Added CVSS V4.0 AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Added CWE CWE-427 Added Reference https://raw.githubusercontent.com/rapid7/metasploit-framework/master/modules/exploits/windows/local/panda_psevents.rb Added Reference https://vulncheck/advisories/panda-security-psevents-insecure-dll-loading-privilege-escalation Added Reference https://web.archive.org/web/20160704105329/http://www.pandasecurity.com/uk/support/card?id=100053 Added Reference https://web.archive.org/web/20170415211828/http://www.security-assessment.com/files/documents/advisory/Panda%20Security%20-%20Privilege%20Escalation.pdf Added Reference https://www.exploit-db.com/exploits/40020