CVE-2025-0889

Feb. 26, 2025, 8:13 a.m.

None
No Score

Description

Prior to 25.2, a local authenticated attacker can elevate privileges on a system with Privilege Management for Windows installed, via the manipulation of COM objects under certain circumstances where an EPM policy allows for automatic privilege elevation of a user process.

Product(s) Impacted

Product Versions
Privilege Management for Windows
  • ['before 25.2']

Weaknesses

Common security weaknesses mapped to this vulnerability.

CWE-268
Privilege Chaining
Two distinct privileges, roles, capabilities, or rights can be combined in a way that allows an entity to perform unsafe actions that would not be allowed without that combination.

Timeline

Published: Feb. 26, 2025, 8:13 a.m.
Last Modified: Feb. 26, 2025, 8:13 a.m.

Status : Awaiting Analysis

CVE has been recently published to the CVE List and has been received by the NVD.

More info

Source

13061848-ea10-403d-bd75-c83a022c2891

*Disclaimer: Some vulnerabilities do not have an associated CPE. To enhance the data, we use AI to infer CPEs based on CVE details. This is an automated process and might not always be accurate.