CVE-2025-0889

Prior to 25.2, a local authenticated attacker can elevate privileges on a system with Privilege Management for Windows installed, via the manipulation of COM objects under certain circumstances where an EPM policy allows for automatic privilege elevation of a user process.
Configurations

Configuration 1 (hide)

cpe:2.3:a:beyondtrust:privilege_management_for_windows:*:*:*:*:*:*:*:*

History

31 Jul 2025, 17:33

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.8
CPE cpe:2.3:a:beyondtrust:privilege_management_for_windows:*:*:*:*:*:*:*:*
Summary
  • (es) Antes de la versión 25.2, un atacante autenticado local puede elevar privilegios en un sistema con Privilege Management para Windows instalado, a través de la manipulación de objetos COM en determinadas circunstancias en las que una política EPM permite la elevación automática de privilegios de un proceso de usuario.
First Time Beyondtrust
Beyondtrust privilege Management For Windows
References () https://www.beyondtrust.com/trust-center/security-advisories/bt25-01 - () https://www.beyondtrust.com/trust-center/security-advisories/bt25-01 - Vendor Advisory

26 Feb 2025, 08:13

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-26 08:13

Updated : 2025-07-31 17:33


NVD link : CVE-2025-0889

Mitre link : CVE-2025-0889

CVE.ORG link : CVE-2025-0889


JSON object : View

Products Affected

beyondtrust

  • privilege_management_for_windows
CWE
CWE-268

Privilege Chaining