CVE-2025-14252: Advantech Susi

High severity, CVSS 7.8. EPSS: 0.1% chance of exploitation in the next 30 days.

An Improper Access Control vulnerability in Advantech SUSI driver (susi.sys) allows attackers to read/write arbitrary memory, I/O ports, and MSRs, resulting in privilege escalation, arbitrary code execution, and information disclosure. This issue affects Advantech SUSI: 5.0.24335 and prior.

Affected products

  • Advantech Susi: up to and including 5.0.24335

Published 2025-12-16. Last modified 2026-10-07.