{"id":"CVE-2025-35471","summary":"conda-forge openssl-feedstock writable OPENSSLDIR","details":"conda-forge openssl-feedstock before 066e83c (2024-05-20), on Microsoft Windows, configures OpenSSL to use an OPENSSLDIR file path that can be written to by non-privilged local users. By writing a specially crafted openssl.cnf file in OPENSSLDIR, a non-privileged local user can execute arbitrary code with the privileges of the user or process loading openssl-feedstock DLLs. Miniforge before 24.5.0 is also affected.","modified":"2026-08-12T03:51:29.512449469Z","published":"2025-05-13T01:13:14.639Z","database_specific":{"unresolved_ranges":[{"extracted_events":[{"fixed":"066e83c"},{"fixed":"24.5.0"}],"source":"AFFECTED_FIELD"},{"source":"DESCRIPTION","extracted_events":[{"fixed":"066e83c"},{"fixed":"24.5.0"}]}],"cna_assigner":"cisa-cg","cwe_ids":["CWE-427"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/35xxx/CVE-2025-35471.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/35xxx/CVE-2025-35471.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-35471"},{"type":"REPORT","url":"https://github.com/conda-forge/openssl-feedstock/issues/201"},{"type":"FIX","url":"https://github.com/conda-forge/openssl-feedstock/commit/066e83c5226bafe90a9c0575b077ce30cd5f5921"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/conda-forge/openssl-feedstock","events":[{"introduced":"0"},{"fixed":"066e83c5226bafe90a9c0575b077ce30cd5f5921"}],"database_specific":{"source":"REFERENCES"}}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-35471.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}]}