HomeSecurityEaton vulnerabilities allow malicious code into the system

Eaton vulnerabilities allow malicious code into the system

A critical security advisory concerns multiple vulnerabilities identified in Eaton UPS Companion (EUC).

See also: New wave of GlassWorm malware targets Mac computers

Eaton vulnerabilities allow malicious code into the system

These vulnerabilities, if exploited, could allow attackers to execute arbitrary code on the host system, potentially giving them complete control over affected devices.

The advisory, codenamed ETN-VA-2025-1026, highlights two specific vulnerabilities that affect all versions of Eaton UPS Companion prior to version 3.0. The company rates the overall risk as high and recommends that users update their software immediately. The most severe issue, referenced as CVE-2025-59887, has a CVSS score of 8.6 (High). The vulnerability is related to unsafe loading of libraries (DLLs) by the software installer.

Security researchers found that an attacker with access to the software package could exploit this weakness to execute arbitrary code. Such vulnerabilities often occur when an application loads dynamic libraries from an unsafe path, allowing malicious files to be loaded instead of legitimate ones.

The second vulnerability, CVE-2025-59888 (CVSS 6.7), is related to a "misquoting" issue in software search paths. In this scenario, if an attacker has access to the local file system, they could place a malicious executable file in a specific location, which the software would unintentionally execute.

See also: EmEditor Editor hacked to distribute infostealer

Eaton vulnerabilities allow malicious code into the system

This vulnerability is specifically related to the way the Windows operating system handles file paths that contain spaces but do not include quotes.

Eaton has released version 3.0 of its UPS Companion software to fix these issues. The company recommends that all customers upgrade to the new secure version immediately.

The update is available for download through Eaton's official distribution channels. For users who are unable to apply the patch immediately, Eaton recommends the following mitigation measures:

  • Restrict local and remote access to the system only to authorized personnel.
  • Placing all control system networks behind properly configured firewalls.
  • Avoid downloading software from unofficial sources to reduce the risk of modification.

See also: MongoDB vulnerability CVE-2025-14847 exploited on a global scale

Eaton vulnerabilities allow malicious code into the system

By regularly updating systems and restricting access, organizations can significantly reduce the risk of exploitation.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS