Junglewise Threat Intelligence

CVE-2025-64699: SevenCs ORCA G2 NULL DACL privilege escalation in regService

CVE-2025-64699 · Severity: high · CVSS 7.8 · Published 2025-12-31

Executive brief

SevenCs ORCA G2 is a maritime electronic chart display and information system (ECDIS) used on ships for navigation and safety. A Windows system service (regService) running with administrator privileges improperly configures security on a raw disk device, removing all access restrictions. This allows any local user to read and write directly to the disk, potentially corrupting critical system files, stealing sensitive data, and gaining administrative control of the vessel's navigation system.

Technical details

The vulnerability is an incorrect permission assignment (CWE-732) affecting the regService component in ORCA G2 v2.0.1.35 / EC2007 Kernel v5.22. The service calls SetFileSecurityA() on the volume device object (e.g., \\.\C:) with DACL_SECURITY_INFORMATION flag, but the supplied security descriptor has no explicitly configured DACL, resulting in a NULL DACL state that effectively grants unrestricted access to everyone. A local authenticated standard user can then open the raw disk device and perform unauthorized read/write operations. Attack vector is local; no network access or prior privilege escalation is required—only local user credentials post-exploitation. An attacker can achieve confidentiality breach (raw disk reads bypass file encryption), integrity loss (raw disk writes corrupt boot sectors and filesystems), and potential privilege escalation via offline credential harvesting. Patch/fix status: Guidance recommends explicit least-privilege DACL configuration and programmatic validation post-change; no public patch version documented yet.

Affected products

  • SevenCs ORCA G2 2.0.1.35

Timeline

  • 2025-12-31: disclosed

References