CWE-269: Improper Privilege Management vulnerability exists for two services (of which one managing audit
trail data and the other acting as server managing client request) that could cause a loss of Confidentiality,
Integrity and Availability of engineering workstation when an attacker with standard privilege modifies the
executable path of the windows services. To be exploited, services need to be restarted.
Metrics
Affected Vendors & Products
References
History
Thu, 13 Feb 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 13 Feb 2025 06:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | CWE-269: Improper Privilege Management vulnerability exists for two services (of which one managing audit trail data and the other acting as server managing client request) that could cause a loss of Confidentiality, Integrity and Availability of engineering workstation when an attacker with standard privilege modifies the executable path of the windows services. To be exploited, services need to be restarted. | |
Weaknesses | CWE-269 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: schneider
Published: 2025-02-13T06:20:26.852Z
Updated: 2025-02-13T14:56:12.017Z
Reserved: 2025-01-08T13:34:15.419Z
Link: CVE-2025-0327

Updated: 2025-02-13T14:56:07.309Z

Status : Received
Published: 2025-02-13T07:15:10.570
Modified: 2025-02-13T07:15:10.570
Link: CVE-2025-0327

No data.