MongoDB Connector for BI installation via MSI on Windows leaves ACLs unset on custom install directories allows Privilege Escalation.This issue affects MongoDB Connector for BI: from 2.0.0 through 2.14.24.
History

Thu, 09 Oct 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 09 Oct 2025 13:00:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft
Microsoft windows
Mongodb
Mongodb connector For Bi
Mongodb mongodb
Vendors & Products Microsoft
Microsoft windows
Mongodb
Mongodb connector For Bi
Mongodb mongodb

Wed, 08 Oct 2025 22:15:00 +0000

Type Values Removed Values Added
Description MongoDB Connector for BI installation via MSI on Windows leaves ACLs unset on custom install directories allows Privilege Escalation.This issue affects MongoDB Connector for BI: from 2.0.0 through 2.14.24.
Title MongoDB Connector for BI installation MSI leave ACLs unset on custom installation directories
Weaknesses CWE-276
References
Metrics cvssV4_0

{'score': 8.8, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mongodb

Published: 2025-10-08T22:07:18.498Z

Updated: 2025-10-10T03:55:24.212Z

Reserved: 2025-10-08T21:16:03.837Z

Link: CVE-2025-11535

cve-icon Vulnrichment

Updated: 2025-10-09T14:32:33.626Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-10-08T22:15:32.557

Modified: 2025-10-09T15:50:04.013

Link: CVE-2025-11535

cve-icon Redhat

No data.