First published: Wed Feb 26 2025(Updated: )
Prior to 25.2, a local authenticated attacker can elevate privileges on a system with Privilege Management for Windows installed, via the manipulation of COM objects under certain circumstances where an EPM policy allows for automatic privilege elevation of a user process.
Credit: 13061848-ea10-403d-bd75-c83a022c2891
Affected Software | Affected Version | How to fix |
---|---|---|
BeyondTrust Privilege Management for Windows and Mac | <25.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-0889 has a moderate severity rating due to its potential for privilege escalation.
To remediate CVE-2025-0889, upgrade BeyondTrust Privilege Management for Windows to version 25.2 or later.
CVE-2025-0889 affects systems running versions of BeyondTrust Privilege Management for Windows prior to 25.2.
CVE-2025-0889 is a local privilege escalation vulnerability.
No, CVE-2025-0889 requires local authenticated access for exploitation.