CVE-2025-0889: Privilege Management for Windows – Elevation of Privilege
Published Feb 26, 2025
·Updated
Prior to 25.2, a local authenticated attacker can elevate privileges on a system with Privilege Management for Windows installed, via the manipulation of COM objects under certain circumstances where an EPM policy allows for automatic privilege elevation of a user process.
Affected Software
2 affected components
BeyondTrust Privilege Management for Windows<25.2
BeyondTrust Privilege Management for Windows<25.2
Event History
Feb 26, 2025
CVE Published
via MITRE·01:41 AM
Data Sourced
via MITRE·01:41 AM
DescriptionWeakness
Data Sourced
via NVD·08:13 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-0889?
CVE-2025-0889 has a moderate severity rating due to its potential for privilege escalation.
2
How do I fix CVE-2025-0889?
To remediate CVE-2025-0889, upgrade BeyondTrust Privilege Management for Windows to version 25.2 or later.
3
Who is affected by CVE-2025-0889?
CVE-2025-0889 affects systems running versions of BeyondTrust Privilege Management for Windows prior to 25.2.
4
What type of vulnerability is CVE-2025-0889?
CVE-2025-0889 is a local privilege escalation vulnerability.
5
Can CVE-2025-0889 be exploited remotely?
No, CVE-2025-0889 requires local authenticated access for exploitation.