CVE-2025-2297
Severity CVSS v4.0:
HIGH
Type:
Unavailable / Other
Publication date:
28/07/2025
Last modified:
04/08/2025
Description
Prior to version 25.4.270.0, a local authenticated attacker can manipulate user profile files to add illegitimate challenge response codes into the local user registry under certain conditions. This allows users with the ability to edit their user profile files to elevate their privileges to administrator.
Impact
Base Score 4.0
7.20
Severity 4.0
HIGH
Base Score 3.x
7.80
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:beyondtrust:privilege_management_for_windows:*:*:*:*:*:*:*:* | 25.4.270 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



