CVE-2025-15554

Browser caching of LAPS passwords in Truesec’s LAPSWebUI before version 2.4 allows an attacker with access to a workstation to escalate their privileges via disclosure of local admin passwords.
Configurations

Configuration 1 (hide)

cpe:2.3:a:truesec:lapswebui:*:*:*:*:*:*:*:*

History

07 Apr 2026, 00:50

Type Values Removed Values Added
References () https://labs.reversec.com/advisories/2026/03/admin-passwords-cached-by-browsers-in-truesec-lapswebui - () https://labs.reversec.com/advisories/2026/03/admin-passwords-cached-by-browsers-in-truesec-lapswebui - Third Party Advisory
First Time Truesec
Truesec lapswebui
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.8
CPE cpe:2.3:a:truesec:lapswebui:*:*:*:*:*:*:*:*
Summary
  • (es) El almacenamiento en caché del navegador de contraseñas LAPS en LAPSWebUI de Truesec antes de la versión 2.4 permite a un atacante con acceso a una estación de trabajo escalar sus privilegios mediante la divulgación de contraseñas de administrador local.

16 Mar 2026, 14:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-16 14:17

Updated : 2026-04-07 00:50


NVD link : CVE-2025-15554

Mitre link : CVE-2025-15554

CVE.ORG link : CVE-2025-15554


JSON object : View

Products Affected

truesec

  • lapswebui
CWE
CWE-525

Use of Web Browser Cache Containing Sensitive Information