Incorrect Default Permissions vulnerability in AIRBUS PSS TETRA Connectivity Server on Windows Server OS allows Privilege Abuse. An attacker may execute arbitrary code with SYSTEM privileges if a user is tricked or directed to place a crafted file into the vulnerable directory. This issue affects TETRA connectivity Server: 7.0. Vulnerability fix is available and delivered to impacted customers.
History

Fri, 03 Apr 2026 14:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 03 Apr 2026 07:45:00 +0000

Type Values Removed Values Added
Description Incorrect Default Permissions vulnerability in AIRBUS PSS TETRA Connectivity Server on Windows Server OS allows Privilege Abuse. An attacker may execute arbitrary code with SYSTEM privileges if a user is tricked or directed to place a crafted file into the vulnerable directory. This issue affects TETRA connectivity Server: 7.0. Vulnerability fix is available and delivered to impacted customers.
Title Local privilege escalation in Windows Server OS through installed Tetra Connectivity Server (TCS)
Weaknesses CWE-276
References
Metrics cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 5.6, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:U'}


cve-icon MITRE

Status: PUBLISHED

Assigner: airbus

Published:

Updated: 2026-04-03T12:16:42.627Z

Reserved: 2025-07-02T14:50:55.096Z

Link: CVE-2025-7024

cve-icon Vulnrichment

Updated: 2026-04-03T12:16:35.708Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-04-03T08:16:17.290

Modified: 2026-04-03T16:10:23.730

Link: CVE-2025-7024

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.