CVE-2025-66374

CyberArk Endpoint Privilege Manager Agent through 25.10.0 allows a local user to achieve privilege escalation through policy elevation of an Administration task.
Configurations

Configuration 1 (hide)

cpe:2.3:a:cyberark:endpoint_privilege_manager:*:*:*:*:*:windows:*:*

History

28 Feb 2026, 04:16

Type Values Removed Values Added
CWE CWE-269
Summary
  • (es) El Agente de CyberArk Endpoint Privilege Manager hasta la versión 25.10.0 permite a un usuario local lograr escalada de privilegios mediante la elevación de política de una tarea de administración.

11 Feb 2026, 16:42

Type Values Removed Values Added
CWE NVD-CWE-noinfo
CPE cpe:2.3:a:cyberark:endpoint_privilege_manager:*:*:*:*:*:windows:*:*
First Time Cyberark endpoint Privilege Manager
Cyberark
References () https://docs.cyberark.com/epm/latest/en/content/release%20notes/rn-whatsnew25-12.htm#Security - () https://docs.cyberark.com/epm/latest/en/content/release%20notes/rn-whatsnew25-12.htm#Security - Release Notes
References () https://www.cyberark.com/ca26-01 - () https://www.cyberark.com/ca26-01 - Permissions Required
References () https://www.cyberark.com/product-security/ - () https://www.cyberark.com/product-security/ - Vendor Advisory

04 Feb 2026, 16:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.8

03 Feb 2026, 18:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-03 18:16

Updated : 2026-02-28 04:16


NVD link : CVE-2025-66374

Mitre link : CVE-2025-66374

CVE.ORG link : CVE-2025-66374


JSON object : View

Products Affected

cyberark

  • endpoint_privilege_manager
CWE
NVD-CWE-noinfo CWE-269

Improper Privilege Management