CVE-2025-27582
Last modified
CVE-2025-27582 is a high-severity vulnerability rated 7.6/10 on the CVSS scale. The Secure Password extension in One Identity Password Manager before 5.14.4 allows local privilege escalation. The issue arises from a flawed security hardening mechanism within the kiosk browser used to display the Password Self-Service site to end users. EPSS estimates a 0.17% chance of exploitation in the next 30 days.
Description
The Secure Password extension in One Identity Password Manager before 5.14.4 allows local privilege escalation. The issue arises from a flawed security hardening mechanism within the kiosk browser used to display the Password Self-Service site to end users. Specifically, the application attempts to restrict privileged actions by overriding the native window.print() function. However, this protection can be bypassed by an attacker who accesses the Password Self-Service site from the lock screen and navigates to an attacker-controlled webpage via the Help function. By hosting a crafted web page with JavaScript, the attacker can restore and invoke the window.print() function, launching a SYSTEM-privileged print dialog. From this dialog, the attacker can exploit standard Windows functionality - such as the Print to PDF or Add Printer wizard - to spawn a command prompt with SYSTEM privileges. Successful exploitation allows a local attacker (with access to a locked workstation) to gain SYSTEM-level privileges, granting full control over the affected device.
Metrics
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-27582?
How severe is CVE-2025-27582?
How do I fix CVE-2025-27582?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-27576Uncontrolled resource consumption for some Edge Orchestrator…2.9
- CVE-2025-27577in OpenHarmony v5.0.3 and prior versions allow a local attac…7
- CVE-2025-27578Pixmeo OsiriX MD is vulnerable to a use after free scenario,…8.7
- CVE-2025-27579In Bitaxe ESP-Miner before 2.5.0 with AxeOS, one can use an …5.4
- CVE-2025-27580NIH BRICS (aka Biomedical Research Informatics Computing Sys…7.5
- CVE-2025-27581NIH BRICS (aka Biomedical Research Informatics Computing Sys…4.3
- CVE-2025-27583Incorrect access control in the component /rest/staffResourc…9.1
- CVE-2025-27584A stored cross-site scripting (XSS) vulnerability in Serosof…5.4
- CVE-2025-27585A stored cross-site scripting (XSS) vulnerability in Serosof…5.4
- CVE-2025-27587OpenSSL 3.0.0 through 3.3.2 on the PowerPC architecture is v…5.3
- CVE-2025-2759GStreamer Incorrect Permission Assignment Local Privilege Es…7.8
- CVE-2025-27590In oxidized-web (aka Oxidized Web) before 0.15.0, the RANCID…9.8
Are you affected by CVE-2025-27582?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
