CVE Database
/

CVE-2025-34109

Back to search

CVE-2025-34109

Published: Jul 15, 2025

Modified: May 15, 2026

PUBLISHED

Description

PSEvents.exe in multiple Panda Security products runs hourly with SYSTEM privileges and loads DLL files from a user-writable directory without proper validation. An attacker with low-privileged access who can write DLL files to the monitored directory can achieve arbitrary code execution with SYSTEM privileges. Affected products include Panda Global Protection 2016, Panda Antivirus Pro 2016, Panda Small Business Protection, and Panda Internet Security 2016 (all versions up to 16.1.2).

VendorProductVersions

Panda Security

Panda Global Protection 2016

affected
0 - <= 16.1.2

Panda Security

Panda Antivirus Pro 2016

affected
0 - <= 16.1.2

Panda Security

Panda Small Business Protection

affected
0 - <= 16.1.2

Panda Security

Panda Internet Security 2016

affected
0 - <= 16.1.2

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now