CVE-2025-63945: Tencent Ioa

High severity, CVSS 7.4. EPSS: 0.2% chance of exploitation in the next 30 days.

A privilege escalation (PE) vulnerability in the Tencent iOA app thru 210.9.28693.621001 on Windows devices enables a local user to execute programs with elevated privileges. However, execution requires that the local user is able to successfully exploit a race condition.

Affected products

  • Tencent Ioa: before 210.9.28693.62001 (fixed in 210.9.28693.62001)

Published 2026-02-23. Last modified 2026-06-17.