High severity7.8NVD Advisory· Published Apr 8, 2025· Updated Jun 17, 2026
CVE-2025-27743
CVE-2025-27743
Description
Untrusted search path in System Center allows an authorized attacker to elevate privileges locally.
Affected products
31cpe:2.3:a:microsoft:system_center_data_protection_manager:2019:-:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:microsoft:system_center_data_protection_manager:2019:-:*:*:*:*:*:*
- cpe:2.3:a:microsoft:system_center_data_protection_manager:2022:-:*:*:*:*:*:*
- cpe:2.3:a:microsoft:system_center_data_protection_manager:2025:-:*:*:*:*:*:*
cpe:2.3:a:microsoft:system_center_operations_manager:2019:-:*:*:*:*:*:*+ 5 more
- cpe:2.3:a:microsoft:system_center_operations_manager:2019:-:*:*:*:*:*:*
- cpe:2.3:a:microsoft:system_center_operations_manager:2022:-:*:*:*:*:*:*
- cpe:2.3:a:microsoft:system_center_operations_manager:2025:-:*:*:*:*:*:*
- (no CPE)range: -
- (no CPE)range: -
- (no CPE)range: -
cpe:2.3:a:microsoft:system_center_orchestrator:2019:-:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:microsoft:system_center_orchestrator:2019:-:*:*:*:*:*:*
- cpe:2.3:a:microsoft:system_center_orchestrator:2022:-:*:*:*:*:*:*
- cpe:2.3:a:microsoft:system_center_orchestrator:2025:-:*:*:*:*:*:*
cpe:2.3:a:microsoft:system_center_service_manager:2019:-:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:microsoft:system_center_service_manager:2019:-:*:*:*:*:*:*
- cpe:2.3:a:microsoft:system_center_service_manager:2022:-:*:*:*:*:*:*
- cpe:2.3:a:microsoft:system_center_service_manager:2025:-:*:*:*:*:*:*
cpe:2.3:a:microsoft:system_center_virtual_machine_manager:2019:-:*:*:*:*:*:*+ 5 more
- cpe:2.3:a:microsoft:system_center_virtual_machine_manager:2019:-:*:*:*:*:*:*
- cpe:2.3:a:microsoft:system_center_virtual_machine_manager:2022:-:*:*:*:*:*:*
- cpe:2.3:a:microsoft:system_center_virtual_machine_manager:2025:-:*:*:*:*:*:*
- (no CPE)range: -
- (no CPE)range: -
- (no CPE)range: -
- Microsoft/System Center Data Protection Manager 2019v5Range: -
- Microsoft/System Center Data Protection Manager 2022v5Range: -
- Microsoft/System Center Data Protection Manager 2025v5Range: -
- Microsoft/System Center Orchestrator 2019v5Range: -
- Microsoft/System Center Orchestrator 2022v5Range: -
- Microsoft/System Center Orchestrator 2025v5Range: -
- Microsoft/System Center Service Manager 2019v5Range: -
- Microsoft/System Center Service Manager 2022v5Range: -
- Microsoft/System Center Service Manager 2025v5Range: -
Patches
Vulnerability mechanics
References
1- msrc.microsoft.com/update-guide/vulnerability/CVE-2025-27743nvdVendor Advisory
News mentions
0No linked articles in our index yet.