← Back

CVE-2025-2297

nvd nist
Published: Jul 28, 2025Modified: Jun 17, 2026

JSON object

Loading...
7.2
Vector
CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Show more
CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XShow less
Source: 13061848-ea10-403d-bd75-c83a022c2891 (Secondary)

Description

Prior to version 25.4.270.0, a local authenticated attacker can manipulate user profile files to add illegitimate challenge response codes into the local user registry under certain conditions. This allows users with the ability to edit their user profile files to elevate their privileges to administrator.

Affected (1)

1 product
Privilege Management For Windows
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 25.4.270

References (1)

Source: 13061848-ea10-403d-bd75-c83a022c2891
Vendor Advisory

Timeline

No history available yet.