CVE-2025-0889

Severity CVSS v4.0:
HIGH
Type:
Unavailable / Other
Publication date:
26/02/2025
Last modified:
31/07/2025

Description

Prior to 25.2, a local authenticated attacker can elevate privileges on a system with Privilege Management for Windows installed, via the manipulation of COM objects under certain circumstances where an EPM policy allows for automatic privilege elevation of a user process.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:beyondtrust:privilege_management_for_windows:*:*:*:*:*:*:*:* 25.2 (excluding)


References to Advisories, Solutions, and Tools