CVE-2025-15554

Severity CVSS v4.0:
MEDIUM
Type:
Unavailable / Other
Publication date:
16/03/2026
Last modified:
07/04/2026

Description

Browser caching of LAPS passwords in Truesec’s LAPSWebUI before version 2.4 allows an attacker with access to a workstation to escalate their privileges via disclosure of local admin passwords.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:truesec:lapswebui:*:*:*:*:*:*:*:* 2.4 (excluding)