CVE Vulnerabilities

CVE-2025-0889

Privilege Chaining

Published: Feb 26, 2025 | Modified: Jul 31, 2025
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Prior to 25.2, a local authenticated attacker can elevate privileges on a system with Privilege Management for Windows installed, via the manipulation of COM objects under certain circumstances where an EPM policy allows for automatic privilege elevation of a user process.

Weakness

Two distinct privileges, roles, capabilities, or rights can be combined in a way that allows an entity to perform unsafe actions that would not be allowed without that combination.

Affected Software

Name Vendor Start Version End Version
Privilege_management_for_windows Beyondtrust * 25.2 (excluding)

Potential Mitigations

References