Cyber Resilience

CVE-2025-66687

High

Published: 16 March 2026

Published
16 March 2026
Modified
27 April 2026
KEV Added
Patch
CVSS Score v3.1 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS Score 0.0073 73.1th percentile
Risk Priority 15 60% EPSS · 20% KEV · 20% CVSS

Summary

CVE-2025-66687 is a high-severity Path Traversal (CWE-22) vulnerability in Jeroscope (inferred from references). Its CVSS base score is 7.5 (High).

Operationally, exploitation aligns with the MITRE ATT&CK technique Exploit Public-Facing Application (T1190); ranked in the top 26.9% of CVEs by exploit likelihood; it is not currently listed in the CISA KEV catalog.

The strongest mitigations our analysis identified are NIST 800-53 SI-10 (Information Input Validation) and SI-2 (Flaw Remediation).

Deeper analysis

CVE-2025-66687 is a Directory Traversal vulnerability (CWE-22) in Doom Launcher 3.8.1.0, stemming from missing file path validation during the extraction of game files. Published on 2026-03-16, it carries a CVSS v3.1 base score of 7.5 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N), highlighting its high confidentiality impact potential.

The vulnerability can be exploited by any remote, unauthenticated attacker requiring no user interaction and low attack complexity. Exploitation enables arbitrary file reads on the affected system, allowing disclosure of sensitive data without impacting integrity or availability.

Advisories providing mitigation guidance are available at https://github.com/nstlaurent/DoomLauncher/issues/369 and https://jeroscope.com/advisories/2025/jero-2025-014/.

EU & UK References

Vulnerability details

Doom Launcher 3.8.1.0 is vulnerable to Directory Traversal due to missing file path validation during the extraction of game files

CWE(s)

Related Threats

MITRE ATT&CK Enterprise TechniquesAI

T1190 Exploit Public-Facing Application Initial Access
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network.
T1005 Data from Local System Collection
Adversaries may search local system sources, such as file systems, configuration files, local databases, virtual machine files, or process memory, to find files of interest and sensitive data prior to Exfiltration.
Why these techniques?

Directory traversal enables remote arbitrary file reads from the local system (T1005) via exploitation of a network-accessible application (T1190).

Confidence: HIGH · MITRE ATT&CK Enterprise v18.1

CVEs Like This One

CVE-2025-12824Shared CWE-22
CVE-2026-25965Shared CWE-22
CVE-2025-30567Shared CWE-22
CVE-2025-27098Shared CWE-22
CVE-2024-55457Shared CWE-22
CVE-2026-35485Shared CWE-22
CVE-2024-54909Shared CWE-22
CVE-2026-3405Shared CWE-22
CVE-2025-41368Shared CWE-22
CVE-2026-23850Shared CWE-22

Affected Assets

Jeroscope
inferred from references and description; NVD did not file a CPE for this CVE

Mitigating Controls

Mitigating Controls (NIST 800-53 r5) AI

prevent

Directly addresses the missing file path validation during game file extraction, preventing directory traversal exploits.

prevent

Requires identification, reporting, and correction of the specific directory traversal flaw in Doom Launcher 3.8.1.0.

prevent

Enforces access control policies to limit file reads to authorized directories, mitigating successful traversal attempts.

References