Unrated severityNVD Advisory· Published Jul 28, 2025· Updated Jul 28, 2025
Privilege Management for Windows - Elevation of Privilege
CVE-2025-2297
Description
Prior to version 25.4.270.0, a local authenticated attacker can manipulate user profile files to add illegitimate challenge response codes into the local user registry under certain conditions. This allows users with the ability to edit their user profile files to elevate their privileges to administrator.
Affected products
1- BeyondTrust/Privilege Management for Windowsv5Range: 0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.