Floragasse 7 – 5th floor, 1040 Vienna
Subscribe to our Newsletter

News

SBA Security Advisory – Cyberduck and Mountain Duck – Improper Certificate Store Handling (CVE-2025-41255)

Vulnerability Overview

Cyberduck and Mountain Duck improper handle TLS certificate pinning for untrusted certificates (e.g., self-signed), unnecessary installing it to the Windows Certificate Store of the current user without any restrictions. This potentially allows attackers to bypass certificate-based authentication or authorization of other programs that trust this certificate store.

  • Type of Vulnerability: CWE-266: Incorrect Privilege Assignment
  • Fixed in Version: Cyberduck 9.1.7 and Mountain Duck 4.17.6
  • CVE ID: CVE-2025-41255
  • CVSS Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:N
  • CVSS Base Score: 8.0 (High)

Recommended Countermeasure

We recommend to update to Cyberduck version 9.1.7 / Mountain Duck version 4.17.6 or later.

Links

Full Security Advisory

Credits

Andreas Boll (SBA Research)
Thomas Kostal (SBA Research)