Description

A local privilege escalation vulnerability has been identified in the Kaba exos 9300 System management application (d9sysdef.exe). Within this application it is possible to specify an arbitrary executable as well as the weekday and start time, when the specified executable should be run with SYSTEM privileges.

INFO

Published Date :

2026-01-26T10:04:05.551Z

Last Modified :

2026-01-26T17:18:41.650Z

Source :

SEC-VLab
AFFECTED PRODUCTS

The following products are affected by CVE-2025-59094 vulnerability.

Vendors Products
Dormakaba
  • Kaba Exos 9300
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2025-59094.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Attack Requirements
Privileges Required
User Interaction
VS Confidentiality
VS Integrity
VS Availability
SS Confidentiality
SS Integrity
SS Availability