Back

HIGH

Privilege Management for Windows - Elevation of Privilege

Published Jul 28, 2025

Description

Prior to version 25.4.270.0, a local authenticated attacker can manipulate user profile files to add illegitimate challenge response codes into the local user registry under certain conditions. This allows users with the ability to edit their user profile files to elevate their privileges to administrator.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner BT
Published Jul 28, 2025
Updated Jul 28, 2025
Reserved Mar 13, 2025
CISA Vulnrichment
Updated Jul 28, 2025
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a