Aller au contenu

Fiche vulnérabilité

CVE-2025-6250 : faille moyenne beyondtrust privilege management for… (CVSS 6.7)

Description

Prior to 25.4.270.0, when wmic.exe is elevated with a full admin token the user can stop the Defendpoint service, bypassing anti-tamper protections. Once the service is disabled, the malicious user can add themselves to Administrators group and run any process with elevated permissions.

En bref

Sévérité
Moyenne (CVSS 6.7)
Vecteur CVSS
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
28 juil. 2025
Dernière mise à jour
17 juin 2026

Produits concernés

  • beyondtrust privilege management for windows

Références

Rechercher une autre vulnérabilité dans la base CVE