Prior to version 25.4.270.0, a local authenticated attacker can manipulate user profile files to add illegitimate challenge response codes into the local user registry under certain conditions. This allows users with the ability to edit their user profile files to elevate their privileges to administrator.
Metrics
Affected Vendors & Products
References
History
Tue, 29 Jul 2025 08:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Beyondtrust
Beyondtrust privilege Management For Windows |
|
Vendors & Products |
Beyondtrust
Beyondtrust privilege Management For Windows |
Mon, 28 Jul 2025 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Mon, 28 Jul 2025 16:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Prior to version 25.4.270.0, a local authenticated attacker can manipulate user profile files to add illegitimate challenge response codes into the local user registry under certain conditions. This allows users with the ability to edit their user profile files to elevate their privileges to administrator. | |
Title | Privilege Management for Windows - Elevation of Privilege | |
Weaknesses | CWE-268 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: BT
Published: 2025-07-28T15:40:14.633Z
Updated: 2025-07-28T17:22:18.590Z
Reserved: 2025-03-13T21:22:29.654Z
Link: CVE-2025-2297

Updated: 2025-07-28T17:22:10.582Z

Status : Awaiting Analysis
Published: 2025-07-28T16:15:24.660
Modified: 2025-07-29T14:14:29.590
Link: CVE-2025-2297

No data.