Hatching Triage Sandbox Windows 10 build 2004 (2025-08-14) and Windows 10 LTSC 2021(2025-08-14) contains a vulnerability in its Windows behavioral analysis engine that allows a submitted malware sample to evade detection and cause denial-of-analysis. The vulnerability is triggered when a sample recursively spawns a large number of child processes, generating high log volume and exhausting system resources. As a result, key malicious behavior, including PowerShell execution and reverse shell activity, may not be recorded or reported, misleading analysts and compromising the integrity and availability of sandboxed analysis results.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://github.com/eGkritsis/CVE-2025-61303 |
|
History
Tue, 28 Oct 2025 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Hatching
Hatching triage Sandbox |
|
| Vendors & Products |
Hatching
Hatching triage Sandbox |
Tue, 21 Oct 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-400 | |
| Metrics |
cvssV3_1
|
Mon, 20 Oct 2025 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Hatching Triage Sandbox Windows 10 build 2004 (2025-08-14) and Windows 10 LTSC 2021(2025-08-14) contains a vulnerability in its Windows behavioral analysis engine that allows a submitted malware sample to evade detection and cause denial-of-analysis. The vulnerability is triggered when a sample recursively spawns a large number of child processes, generating high log volume and exhausting system resources. As a result, key malicious behavior, including PowerShell execution and reverse shell activity, may not be recorded or reported, misleading analysts and compromising the integrity and availability of sandboxed analysis results. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-10-21T13:47:55.289Z
Reserved: 2025-09-26T00:00:00.000Z
Link: CVE-2025-61303
Updated: 2025-10-21T13:47:51.696Z
Status : Awaiting Analysis
Published: 2025-10-20T21:15:38.330
Modified: 2025-10-21T19:31:25.450
Link: CVE-2025-61303
No data.