CVE-2025-2297: CWE-268 in BeyondTrust Privilege Management for Windows
Prior to version 25.4.270.0, a local authenticated attacker can manipulate user profile files to add illegitimate challenge response codes into the local user registry under certain conditions. This allows users with the ability to edit their user profile files to elevate their privileges to administrator.
CVE-2025-2297: CWE-268 in BeyondTrust Privilege Management for Windows
Description
Prior to version 25.4.270.0, a local authenticated attacker can manipulate user profile files to add illegitimate challenge response codes into the local user registry under certain conditions. This allows users with the ability to edit their user profile files to elevate their privileges to administrator.
Technical Details
- Data Version
- 5.1
- Assigner Short Name
- BT
- Date Reserved
- 2025-03-13T21:22:29.654Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 68879b9aad5a09ad0084eb2c
Added to database: 7/28/2025, 3:47:38 PM
Last updated: 7/28/2025, 3:47:38 PM
Views: 1
Related Threats
CVE-2025-6250: CWE-424 in BeyondTrust Privilege Management for Windows
HighCVE-2025-32731: CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in MedDream MedDream PACS Premium
MediumCVE-2025-27724: CWE-284: Improper Access Control in MedDream MedDream PACS Premium
CriticalCVE-2025-26469: CWE-732: Incorrect Permission Assignment for Critical Resource in MedDream MedDream PACS Premium
CriticalCVE-2025-24485: CWE-918: Server-Side Request Forgery (SSRF) in MedDream MedDream PACS Premium
MediumActions
External Links
Need enhanced features?
Contact root@offseq.com for Pro access with improved analysis and higher rate limits.