Aller au contenu

Fiche vulnérabilité

CVE-2025-2297 : faille élevée beyondtrust privilege management for… (CVSS 7.8)

Description

Prior to version 25.4.270.0, a local authenticated attacker can manipulate user profile files to add illegitimate challenge response codes into the local user registry under certain conditions. This allows users with the ability to edit their user profile files to elevate their privileges to administrator.

En bref

Sévérité
Élevée (CVSS 7.8)
Vecteur CVSS
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
28 juil. 2025
Dernière mise à jour
17 juin 2026

Produits concernés

  • beyondtrust privilege management for windows

Références

Rechercher une autre vulnérabilité dans la base CVE