Junglewise Threat Intelligence

CVE-2025-14018: NetBT e-Fatura unquoted search path vulnerability

CVE-2025-14018 · Severity: high · CVSS 7.3 · Published 2025-12-22

Executive brief

NetBT e-Fatura, an electronic invoicing solution, contains a security vulnerability that could allow a local user to gain unauthorized control over the system. By placing a malicious file in a specific location on the computer, an attacker can trick the software into running their code instead of the intended program. This could lead to the theft of sensitive financial data or a complete takeover of the affected workstation.

Technical details

An Unquoted Search Path or Element vulnerability (CWE-428) exists in NetBT Consulting Services Inc. e-Fatura versions prior to 1.2.15. The application fails to wrap executable paths in quotation marks, which allows a local attacker with write permissions to the parent directory to intercept service calls by placing a malicious executable or library in the search path. Successful exploitation enables local privilege escalation or arbitrary code execution under the context of the application's service account. The vulnerability is mitigated in version 1.2.15.

Affected products

  • NetBT Consulting Services Inc. e-Fatura before 1.2.15

Timeline

  • 2025-12-22: advisory: Initial disclosure by TR-CERT (USOM)

References