Altera Quartus Prime Standard and Lite Installers Uncontrolled Search Path Element Vulnerability

Vulnerability

A search order hijacking vulnerability has been identified in the Altera Quartus Prime Standard and Lite Edition Installers (SFX) for Windows, versions 23.1 through 24.1. This vulnerability allows for a binary planting attack, where malicious binaries can be planted and potentially executed, leading to unauthorized actions or privilege escalation. The issue does not affect the Linux versions of Quartus Prime.

Impact

Exploitation of this vulnerability could lead to unauthorized privilege escalation by allowing malicious binaries to be executed with elevated rights.

Remediation

Users are advised to upgrade to Quartus 25.1 Standard Edition or Quartus 25.1 Lite Edition. For those using older versions, downloading the individual installation files directly from the Altera download page will avoid this vulnerability, as these files are not affected.

Added: Jan 7, 2026, 2:05 AM
Updated: Jan 7, 2026, 2:05 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
2.9
remediation
0.0
relevance
1.9
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.