VYPR

Orca G2

by SevenCs

CVEs (2)

  • CVE-2025-64699HigDec 31, 2025
    risk 0.51cvss 7.8epss 0.00

    An incorrect NULL DACL issue exists in SevenCs ORCA G2 2.0.1.35 (EC2007 Kernel v5.22). The regService process, which runs with SYSTEM privileges, applies a Security Descriptor to a device object with no explicitly configured DACL. This condition could allow an attacker to…

  • CVE-2025-61037HigDec 31, 2025
    risk 0.46cvss 7.0epss 0.00

    A local privilege escalation vulnerability exists in SevenCs ORCA G2 2.0.1.35 (EC2007 Kernel v5.22). The flaw is a Time-of-Check Time-of-Use (TOCTOU) race condition in the license management logic. The regService process, which runs with SYSTEM privileges, creates a fixed…