Local privilege escalation through insecure DCOM configuration in Valmet DNA versions prior to C2023. The DCOM object Valmet DNA Engineering has permissions that allow it to run commands as a user with the SeImpersonatePrivilege privilege. The SeImpersonatePrivilege privilege is a Windows permission that allows a process to impersonate another user. An attacker can use this vulnerability to escalate their privileges and take complete control of the system.
Metrics
Affected Vendors & Products
References
History
Tue, 01 Apr 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 01 Apr 2025 04:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Local privilege escalation through insecure DCOM configuration in Valmet DNA versions prior to C2023. The DCOM object Valmet DNA Engineering has permissions that allow it to run commands as a user with the SeImpersonatePrivilege privilege. The SeImpersonatePrivilege privilege is a Windows permission that allows a process to impersonate another user. An attacker can use this vulnerability to escalate their privileges and take complete control of the system. | |
Title | Valmet DNA Local privilege escalation through insecure DCOM configuration | |
Weaknesses | CWE-269 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: NCSC-FI
Published: 2025-04-01T04:05:14.236Z
Updated: 2025-04-01T14:13:36.829Z
Reserved: 2025-01-13T12:24:09.743Z
Link: CVE-2025-0416

Updated: 2025-04-01T14:13:32.247Z

Status : Awaiting Analysis
Published: 2025-04-01T04:15:37.727
Modified: 2025-04-01T20:26:11.547
Link: CVE-2025-0416

No data.