PatchSiren cyber security CVE debrief
CVE-2025-10314 Mitsubishi Electric CVE debrief
CVE-2025-10314 is a high-severity local code execution issue in Mitsubishi Electric FREQSHIP-mini for Windows. CISA’s advisory says incorrect default permissions can let a local attacker replace the service executable or DLL files in the installation directory with crafted files, leading to arbitrary code execution with system privileges. Mitsubishi Electric says the issue is addressed in version 8.1.0 or later.
- Vendor
- Mitsubishi Electric
- Product
- FREQSHIP-mini for Windows
- CVSS
- HIGH 8.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-02-03
- Original CVE updated
- 2026-02-03
- Advisory published
- 2026-02-03
- Advisory updated
- 2026-02-03
Who should care
Organizations running Mitsubishi Electric FREQSHIP-mini for Windows, especially Windows administrators and OT/ICS teams responsible for UPS shutdown tooling on systems that may be locally accessed or remotely reachable.
Technical summary
The advisory describes a software installation directory permissions problem in FREQSHIP-mini for Windows. Because default permissions are incorrect, a local attacker may be able to swap service executable or DLL files with specially crafted versions and trigger execution with system privileges. The supplied CVSS vector is CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H (8.8 High).
Defensive priority
High. Apply the vendor fix as soon as practical, because the flaw can result in system-privileged code execution and the vendor has provided a specific fixed release.
Recommended defensive actions
- Upgrade FREQSHIP-mini for Windows to version 8.1.0 or later from Mitsubishi Electric’s download site.
- Limit use of affected PCs to a LAN and block remote logins from untrusted networks, hosts, and non-administrator users.
- Use a firewall or VPN to block unauthorized access, and allow remote login only for administrators when internet exposure is unavoidable.
- Restrict physical access to the PC and its connected network.
- Do not click links or open attachments from untrusted sources.
- Install and regularly update antivirus software.
Evidence notes
The source corpus is CISA CSAF advisory ICSA-26-034-01, published 2026-02-03, with revision history noting an initial republication of Mitsubishi Electric 2025-019. The advisory and vendor remediation both identify incorrect default permissions as the root cause and list version 8.1.0 or later as the fixed release. No KEV listing or ransomware-use data was supplied.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-10314 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-10314
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-10314 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-10314
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-034-01.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-034-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ncas/tips/ST04-014
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.