PSEvents.exe in multiple Panda Security products runs hourly with SYSTEM privileges and loads DLL files from a user-writable directory without proper validation. An attacker with low-privileged access who can write DLL files to the monitored directory can achieve arbitrary code execution with SYSTEM privileges. Affected products include Panda Global Protection 2016, Panda Antivirus Pro 2016, Panda Small Business Protection, and Panda Internet Security 2016 (all versions up to 16.1.2).
Advisories
Source ID Title
EUVD EUVD EUVD-2025-21431 PSEvents.exe in multiple Panda Security products runs hourly with SYSTEM privileges and loads DLL files from a user-writable directory without proper validation. An attacker with low-privileged access who can write DLL files to the monitored directory can achieve arbitrary code execution with SYSTEM privileges. Affected products include Panda Global Protection 2016, Panda Antivirus Pro 2016, Panda Small Business Protection, and Panda Internet Security 2016 (all versions up to 16.1.2).
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 21 Nov 2025 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Pandasecurity
Pandasecurity panda Antivirus Pro
Pandasecurity panda Global Protection 2016
Pandasecurity panda Internet Security 2014
CPEs cpe:2.3:a:pandasecurity:panda_antivirus_pro:*:*:*:*:*:*:*:*
cpe:2.3:a:pandasecurity:panda_global_protection_2016:*:*:*:*:*:*:*:*
cpe:2.3:a:pandasecurity:panda_internet_security_2014:*:*:*:*:*:*:*:*
Vendors & Products Pandasecurity
Pandasecurity panda Antivirus Pro
Pandasecurity panda Global Protection 2016
Pandasecurity panda Internet Security 2014

Wed, 16 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00014}


Tue, 15 Jul 2025 14:30:00 +0000


Tue, 15 Jul 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Jul 2025 14:00:00 +0000


Tue, 15 Jul 2025 13:15:00 +0000

Type Values Removed Values Added
Description PSEvents.exe in multiple Panda Security products runs hourly with SYSTEM privileges and loads DLL files from a user-writable directory without proper validation. An attacker with low-privileged access who can write DLL files to the monitored directory can achieve arbitrary code execution with SYSTEM privileges. Affected products include Panda Global Protection 2016, Panda Antivirus Pro 2016, Panda Small Business Protection, and Panda Internet Security 2016 (all versions up to 16.1.2).
Title Panda Security PSEvents.exe Insecure DLL Loading Privilege Escalation
Weaknesses CWE-427
References
Metrics cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2025-11-21T19:20:03.072Z

Reserved: 2025-04-15T19:15:22.560Z

Link: CVE-2025-34109

cve-icon Vulnrichment

Updated: 2025-07-15T13:37:10.250Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-07-15T13:15:30.683

Modified: 2025-07-15T20:07:28.023

Link: CVE-2025-34109

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses