Junglewise Threat Intelligence

CVE-2025-1161: NomySoft Nomysem privilege escalation via incorrect API use

CVE-2025-1161 · Severity: high · CVSS 7.1 · Published 2025-12-10

Executive brief

Nomysem, a software solution from NomySoft, contains a security flaw that could allow a standard user to gain unauthorized administrative privileges. By exploiting an error in how the system handles sensitive internal functions, an attacker could take full control of the application, potentially accessing or modifying sensitive training and consulting data. This could lead to a total compromise of the system's integrity and confidentiality.

Technical details

A privilege escalation vulnerability exists in NomySoft Nomysem (through May 2025) due to the incorrect use of privileged APIs (CWE-648). The vulnerability allows an attacker with low-level privileges to execute functions or access data typically reserved for higher-privileged accounts. Exploitation requires network access and is characterized by high complexity, potentially requiring specific timing or user interaction. If successful, an attacker can achieve full compromise of confidentiality, integrity, and availability (C/I/A) within the application environment.

Affected products

  • NomySoft Information Technology Training and Consulting Inc. Nomysem through May 2025

Timeline

  • 2025-12-10: disclosed
  • 2025-12-10: advisory

References