High severity7.8NVD Advisory· Published Jul 28, 2025· Updated Jun 17, 2026
CVE-2025-2297
CVE-2025-2297
Description
Prior to version 25.4.270.0, a local authenticated attacker can manipulate user profile files to add illegitimate challenge response codes into the local user registry under certain conditions. This allows users with the ability to edit their user profile files to elevate their privileges to administrator.
Affected products
3cpe:2.3:a:beyondtrust:privilege_management_for_windows:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:beyondtrust:privilege_management_for_windows:*:*:*:*:*:*:*:*range: <25.4.270
- (no CPE)range: 0
- Range: <25.4.270.0
Patches
Vulnerability mechanics
References
1- www.beyondtrust.com/trust-center/security-advisories/bt25-05nvdVendor Advisory
News mentions
0No linked articles in our index yet.