CVE-2025-2297
Last modified
CVE-2025-2297 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. Prior to version 25.4.270.0, a local authenticated attacker can manipulate user profile files to add illegitimate challenge response codes into the local user registry under certain conditions. This allows users with the ability to edit their user profile files to elevate their privileges to administrator.. EPSS estimates a 0.13% chance of exploitation in the next 30 days.
Description
Prior to version 25.4.270.0, a local authenticated attacker can manipulate user profile files to add illegitimate challenge response codes into the local user registry under certain conditions. This allows users with the ability to edit their user profile files to elevate their privileges to administrator.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Beyondtrust | Privilege Management For Windows | < 25.4.270 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-2297?
How severe is CVE-2025-2297?
How do I fix CVE-2025-2297?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-22960A session hijacking vulnerability exists in the web-based ma…8
- CVE-2025-22961A critical information disclosure vulnerability exists in th…8
- CVE-2025-22962A critical remote code execution (RCE) vulnerability exists …7.2
- CVE-2025-22963Teedy through 1.11 allows CSRF for account takeover via POST…7.5
- CVE-2025-22964DDSN Interactive cm3 Acora CMS version 10.1.1 has an unauthe…8.1
- CVE-2025-22968An issue in D-Link DWR-M972V 1.05SSG allows a remote attacke…9.8
- CVE-2025-22973An issue in QiboSoft QiboCMS X1.0 allows a remote attacker t…7.5
- CVE-2025-22974SQL Injection vulnerability in SeaCMS v.13.2 and before allo…9.8
- CVE-2025-22976SQL Injection vulnerability in dingfanzuCMS v.1.0 allows a l…7.1
- CVE-2025-22978eladmin <=2.7 is vulnerable to CSV Injection in the exceptio…9.8
- CVE-2025-2298An improper authorization vulnerability in Dremio Software a…8.4
- CVE-2025-22980A SQL Injection vulnerability exists in Senayan Library Mana…6.7
Are you affected by CVE-2025-2297?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
