Junglewise Threat Intelligence

CVE-2026-25265: Qualcomm component privilege escalation in temporary file handling

CVE-2026-25265 · Severity: high · CVSS 8.8 · Published 2026-09-22

Technologies: Microsoft Windows. Vendors: Microsoft, Qualcomm.

Executive brief

A Qualcomm component contains a privilege escalation vulnerability in how it handles temporary files due to weak security configuration. An attacker with local access could exploit this to gain elevated privileges on the affected system, potentially leading to complete system compromise or unauthorized access to sensitive data.

Technical details

The vulnerability exists in Qualcomm component's temporary file handling mechanism, which uses weak file permissions or predictable naming conventions that allow local privilege escalation. An attacker with local system access can exploit the insecure temporary file configuration to escalate privileges to a higher level. No patch information is currently available in the provided advisory.

Affected products

  • Qualcomm <UNKNOWN> <UNKNOWN>

Timeline

  • 2026-09-22: disclosed

References

Related threats