Back

HIGH

Privilege Management for Windows – Elevation of Privilege

Published Feb 26, 2025

Description

Prior to 25.2, a local authenticated attacker can elevate privileges on a system with Privilege Management for Windows installed, via the manipulation of COM objects under certain circumstances where an EPM policy allows for automatic privilege elevation of a user process.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (2)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner BT
Published Feb 26, 2025
Updated Feb 26, 2025
Reserved Jan 30, 2025

CISA Vulnrichment

Updated Feb 26, 2025

NVD

Status Analyzed
Modified Jun 17, 2026

Red Hat

No data

ENISA EUVD

Assigner BT
Published Feb 26, 2025
Updated Feb 26, 2025

GitHub

No data