Eaton Vulnerabilities Let Attackers Execute Arbitrary Code On the Host System
A critical security advisory has been issued for multiple vulnerabilities identified in the Eaton UPS Companion (EUC) software. Exploitation of these vulnerabilities could enable attackers to execute arbitrary code on the host system, potentially…
A critical security advisory has been issued for multiple vulnerabilities identified in the Eaton UPS Companion (EUC) software. Exploitation of these vulnerabilities could enable attackers to execute arbitrary code on the host system, potentially granting them full control over affected devices.
The advisory, labeled ETN-VA-2025-1026, outlines two specific vulnerabilities present in all versions of the Eaton UPS Companion software prior to version 3.0. The vulnerabilities are classified as follows:
CVE ID Severity Flaw Type Issue Summary
CVE-2025-59887 High (8.6) Insecure Library Loading A flaw in the installer allows attackers to execute malicious code by exploiting insecure library loading.
CVE-2025-59888 Medium (6.7) Unquoted Search Path An unquoted search path issue enables local attackers to execute malicious files on the system.
A critical security advisory has been issued for multiple vulnerabilities identified in the Eaton UPS Companion (EUC) software.
The most critical issue, tracked as CVE-2025-59887, carries a CVSS score of 8.6 (High). This vulnerability arises from insecure library loading within the software installer. Attackers with access to the software package could leverage this flaw to execute arbitrary code.
This vulnerability is commonly associated with applications loading dynamic link libraries (DLLs) from insecure paths, which could allow the loading of malicious files instead of legitimate ones.
The second vulnerability, CVE-2025-59888 (CVSS 6.7), involves an improper quotation issue in the software's search paths. An attacker with access to the local file system could position a malicious executable in a specific location that the software unintentionally executes. This flaw particularly exploits how the Windows operating system manages file paths containing spaces without quotation marks.
To mitigate these vulnerabilities, Eaton has released version 3.0 of the UPS Companion software. Users are strongly advised to update to this secure version immediately. The update is available through Eaton's official software distribution channels.
For users unable to apply the patch immediately, Eaton recommends the following mitigation measures:
Restrict local and remote access to the host system to authorized personnel only. Ensure that all control system networks are protected by securely configured firewalls. Avoid downloading software from unofficial sources to prevent tampering.
By keeping systems updated and restricting access, organizations can significantly minimize the risk of exploitation.
Based on reporting by Cyber Security News.
