CVE-2025-51726 affects CyberGhostVPNSetup.exe, the Windows installer for CyberGhost VPN. According to the provided content, the installer is Authenticode-signed using the deprecated SHA-1 cryptographic hash algorithm, which is susceptible to collision attacks. This weakness can enable an attacker to craft a malicious installer and attempt to present it as legitimately signed, particularly on Windows systems where SmartScreen, certificate trust policy, or related signature enforcement is not strict. The same installer also lacks High Entropy Address Space Layout Randomization (ASLR), as reportedly confirmed by BinSkim BA2015 findings and repeated WinDbg observations showing predictable image loading ranges. The absence of high-entropy ASLR reduces memory layout randomness and can make exploitation of memory corruption conditions more reliable. Based on the supplied information, the issue is a combination of weak code-signing cryptography and insecure binary hardening in the Windows installer.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No valid public exploits. Mallory filtered out 1 candidate as fakes, detection scripts, or README-only repos.
All candidate exploits were filtered out by Mallory's validation.
2 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.