CVE-2025-0889
Feb. 26, 2025, 8:13 a.m.
None
No Score
Description
Prior to 25.2, a local authenticated attacker can elevate privileges on a system with Privilege Management for Windows installed, via the manipulation of COM objects under certain circumstances where an EPM policy allows for automatic privilege elevation of a user process.
Product(s) Impacted
| Product | Versions |
|---|---|
| Privilege Management for Windows |
|
Weaknesses
Common security weaknesses mapped to this vulnerability.
CWE-268
Privilege Chaining
Two distinct privileges, roles, capabilities, or rights can be combined in a way that allows an entity to perform unsafe actions that would not be allowed without that combination.
Tags
Timeline
Published: Feb. 26, 2025, 8:13 a.m.
Last Modified: Feb. 26, 2025, 8:13 a.m.
Last Modified: Feb. 26, 2025, 8:13 a.m.
Status : Awaiting Analysis
CVE has been recently published to the CVE List and has been received by the NVD.
More infoSource
13061848-ea10-403d-bd75-c83a022c2891
*Disclaimer: Some vulnerabilities do not have an associated CPE. To enhance the data, we use AI to infer CPEs based on CVE details. This is an automated process and might not always be accurate.