CVE-2025-11535: MongoDB Connector for BI installation MSI leave ACLs unset on custom installation directories
MongoDB Connector for BI installation via MSI on Windows leaves ACLs unset on custom install directories allows Privilege Escalation.This issue affects MongoDB Connector for BI: from 2.0.0 through 2.14.24.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-11535?
CVE-2025-11535 is classified as a medium severity vulnerability due to the potential for privilege escalation.
How do I fix CVE-2025-11535?
To mitigate CVE-2025-11535, ensure that custom install directories for MongoDB Connector for BI have the appropriate ACLs set to restrict unauthorized access.
What versions are affected by CVE-2025-11535?
CVE-2025-11535 affects MongoDB Connector for BI versions from 2.0.0 through 2.14.24.
What type of vulnerability is CVE-2025-11535?
CVE-2025-11535 is a privilege escalation vulnerability linked to the misconfiguration of access control lists (ACLs).
Can CVE-2025-11535 be exploited remotely?
CVE-2025-11535 requires local access to the installation directory, thus it is not a remotely exploitable vulnerability.